PT-2006-1070 · X.Org+2 · Libxfont+3

Published

2006-09-12

·

Updated

2018-10-17

·

CVE-2006-3739

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: libXfont versions prior to 1.2.1 X.Org version 6.8.2 XFree86 X server (affected versions not specified)
Description: The issue concerns multiple vulnerabilities in the libXfont package and X.Org/XFree86 X server, which can be exploited locally to compromise the confidentiality, integrity, and availability of protected information. Specifically, an integer overflow in the CIDAFM function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted Adobe Font Metrics (AFM) files with a modified number of character metrics (StartCharMetrics), leading to a heap-based buffer overflow.
Recommendations: For libXfont versions prior to 1.2.1, update to version 1.2.1 or later. For X.Org version 6.8.2, consider disabling the CIDAFM function as a temporary workaround until a patch is available. For XFree86 X server, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-09527
CVE-2006-3739
DSA-1193-1
RHSA-2006:0665
RHSA-2006:0666
RHSA-2006_0665

Affected Products

Red Hat
X.Org
Xfree86 X Server
Libxfont