Description
Integer overflow in the scan_cidfont function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted (1) CMap and (2) CIDFont font data with modified item counts in the (a) begincodespacerange, (b) cidrange, and (c) notdefrange sections.
CVSS vector
AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0 Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-gpr2-3wwv-wvmr: Integer overflow in the scan_cidfont function in X↗2022-05-01 ▶ CVEListCVE-2006-3740: Integer overflow in the scan_cidfont function in X↗2006-09-13 ▶ OSVCVE-2006-3740: Integer overflow in the scan_cidfont function in X↗2006-09-13 ▶ 📋Vendor Advisories
3UbuntuX.org vulnerabilities↗2006-09-13 ▶ DebianCVE-2006-3740: libxfont - Integer overflow in the scan_cidfont function in X.Org 6.8.2 and XFree86 X serve...↗2006 ▶ 💬Community
4BugzillaCVE-2006-3740 security flaw↗2018-08-16 ▶ BugzillaCVE-2006-3739 X CID font parser multiple integer overflows (CVE-2006-3740)↗2006-09-15 ▶ BugzillaCVE-2006-3739 X CID font parser multiple integer overflows (CVE-2006-3740)↗2006-08-29 ▶ BugzillaCVE-2006-3739 X CID font parser multiple integer overflows (CVE-2006-3740)↗2006-08-29 ▶