PT-2006-7608 · X.Org+2 · Libxfont+2
CVE-2006-3467
·
Publicado
1970-01-01
·
Atualizado
2023-02-13
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
libXfont versions prior to 1.2.0
freetype2-64bit (affected versions not specified)
freetype2-devel-64bit (affected versions not specified)
freetype2-x86 (affected versions not specified)
FreeType versions prior to 2.2
Description
The issue is related to an integer overflow in FreeType, which can be exploited remotely. This may lead to a denial of service (crash) and potentially allow the execution of arbitrary code via a crafted PCF file. The vulnerability can compromise the confidentiality, integrity, and availability of protected information.
Recommendations
For libXfont versions prior to 1.2.0, update to version 1.2.0 or later.
For freetype2-64bit, freetype2-devel-64bit, and freetype2-x86, update to a version that includes the fix for the integer overflow issue.
For FreeType versions prior to 2.2, update to version 2.2 or later.
As a temporary workaround, consider restricting access to crafted PCF files to minimize the risk of exploitation.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Freetype
Red Hat
Libxfont