CVE Vulnerabilities

CVE-2006-3740

Published: Sep 13, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Integer overflow in the scan_cidfont function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted (1) CMap and (2) CIDFont font data with modified item counts in the (a) begincodespacerange, (b) cidrange, and (c) notdefrange sections.

Affected Software

NameVendorStart VersionEnd Version
X.orgX.org6.8.2 (including)6.8.2 (including)
Xfree86_xXfree86_project**
Red Hat Enterprise Linux 3RedHatXFree86-0:4.3.0-113.EL*
Red Hat Enterprise Linux 4RedHatxorg-x11-0:6.8.2-1.EL.13.37.2*
LibxfontUbuntudapper*
LibxfontUbuntuedgy*
LibxfontUbuntuupstream*

References