CVE Vulnerabilities

CVE-2006-3740

Published: Sep 13, 2006 | Modified: Oct 17, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Integer overflow in the scan_cidfont function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted (1) CMap and (2) CIDFont font data with modified item counts in the (a) begincodespacerange, (b) cidrange, and (c) notdefrange sections.

Affected Software

Name Vendor Start Version End Version
X.org X.org 6.8.2 (including) 6.8.2 (including)
Xfree86_x Xfree86_project * *
Red Hat Enterprise Linux 3 RedHat XFree86-0:4.3.0-113.EL *
Red Hat Enterprise Linux 4 RedHat xorg-x11-0:6.8.2-1.EL.13.37.2 *
Libxfont Ubuntu dapper *
Libxfont Ubuntu edgy *
Libxfont Ubuntu upstream *

References