Description
Integer overflow in FreeType before 2.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PCF file, as demonstrated by the Red Hat bad1.pcf test file, due to a partial fix of CVE-2006-1861.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4 Affected Packages3 packages
🔴Vulnerability Details
3GHSAGHSA-f3f6-hw6f-fq9r: Integer overflow in FreeType before 2↗2022-05-03 ▶ OSVCVE-2006-3467: Integer overflow in FreeType before 2↗2006-07-21 ▶ CVEListCVE-2006-3467: Integer overflow in FreeType before 2↗2006-07-18 ▶ 📋Vendor Advisories
4Ubuntulibxfont vulnerability↗2006-09-07 ▶ Ubuntufreetype vulnerability↗2006-07-28 ▶ Red Hatfreetype: integer overflow vulnerability due to incomplete fix for CVE-2006-1861↗2006-07-18 ▶ DebianCVE-2006-3467: freetype - Integer overflow in FreeType before 2.2 allows remote attackers to cause a denia...↗2006 ▶ 💬Community
4Bugzillanx: Appears to embed a vulnerable version of libXfont prone to CVE-2008-0006↗2010-12-03 ▶ BugzillaCVE-2006-3467 freetype: integer overflow vulnerability due to incomplete fix for CVE-2006-1861↗2009-02-23 ▶ BugzillaCVE-2006-3467 Xorg PCF handling Integer overflow↗2006-08-15 ▶ BugzillaCVE-2006-1861 freetype multiple integer overflows (CVE-2006-3467)↗2006-05-03 ▶