CVE-2006-3740

Source
https://nvd.nist.gov/vuln/detail/CVE-2006-3740
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2006-3740.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2006-3740
Related
Published
2006-09-13T01:07:00Z
Modified
2024-11-21T00:14:18Z
Summary
[none]
Details

Integer overflow in the scan_cidfont function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted (1) CMap and (2) CIDFont font data with modified item counts in the (a) begincodespacerange, (b) cidrange, and (c) notdefrange sections.

References

Affected packages

Debian:11 / libxfont

Package

Name
libxfont
Purl
pkg:deb/debian/libxfont?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.2.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / libxfont

Package

Name
libxfont
Purl
pkg:deb/debian/libxfont?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.2.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / libxfont

Package

Name
libxfont
Purl
pkg:deb/debian/libxfont?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.2.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}