{"id":"DEBIAN-CVE-2003-0581","details":"X Fontserver for Truetype fonts (xfstt) 1.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a (1) FS_QueryXExtents8 or (2) FS_QueryXBitmaps8 packet, and possibly other types of packets, with a large num_ranges value, which causes an out-of-bounds array access.","modified":"2026-08-04T06:01:56.661612055Z","published":"2003-08-18T04:00:00Z","upstream":["CVE-2003-0581"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2003-0581"}],"affected":[{"package":{"name":"xfstt","ecosystem":"Debian:11","purl":"pkg:deb/debian/xfstt?arch=source&distro=bullseye"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2003-0581.json"}}],"schema_version":"1.8.0"}