CVE Vulnerabilities

CVE-2006-3467

Published: Jul 21, 2006 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Integer overflow in FreeType before 2.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PCF file, as demonstrated by the Red Hat bad1.pcf test file, due to a partial fix of CVE-2006-1861.

Affected Software

Name Vendor Start Version End Version
Freetype Freetype * 2.1 (including)
Red Hat Enterprise Linux 3 RedHat freetype-0:2.1.4-4.0.rhel3.2 *
Red Hat Enterprise Linux 3 RedHat XFree86-0:4.3.0-111.EL *
Red Hat Enterprise Linux 4 RedHat freetype-0:2.1.9-1.rhel4.4 *
Red Hat Enterprise Linux 4 RedHat xorg-x11-0:6.8.2-1.EL.13.37 *
Freetype Ubuntu dapper *
Freetype Ubuntu devel *
Freetype Ubuntu edgy *
Freetype Ubuntu feisty *
Freetype Ubuntu gutsy *
Freetype Ubuntu hardy *
Freetype Ubuntu intrepid *
Freetype Ubuntu jaunty *
Freetype Ubuntu karmic *
Freetype Ubuntu upstream *
Ia32-libs Ubuntu dapper *
Ia32-libs Ubuntu gutsy *
Libxfont Ubuntu dapper *
Libxfont Ubuntu devel *
Libxfont Ubuntu edgy *
Libxfont Ubuntu feisty *
Libxfont Ubuntu gutsy *
Libxfont Ubuntu hardy *
Libxfont Ubuntu intrepid *
Libxfont Ubuntu jaunty *
Libxfont Ubuntu karmic *

References