CVE-2006-3467

Summary

CVECVE-2006-3467
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2006-07-21 14:03:00 UTC
Updated2023-02-13 02:16:00 UTC
DescriptionInteger overflow in FreeType before 2.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PCF file, as demonstrated by the Red Hat bad1.pcf test file, due to a partial fix of CVE-2006-1861.

Risk And Classification

Problem Types: CWE-189

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Freetype Freetype All All All All

References

ReferenceSourceLinkTags
Sun Solaris FreeType Integer Overflow and Underflow Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
2006-0052 TRUSTIX www.trustix.org
Debian -- Security Information -- DSA-1178-1 freetype DEBIAN www.debian.org
SecurityFocus BUGTRAQ www.securityfocus.com
SecurityTracker.com Archives - FreeType Integer Overflows Let Remote Users Execute Arbitrary Code SECTRACK securitytracker.com
Support REDHAT www.redhat.com Vendor Advisory
SuSE Security announcements: [suse-security-announce] SUSE Security Announcement: freetype2 (SUSE-SA:2006:045) SUSE lists.suse.com
[security-announce] SUSE Security Summary Report SUSE-SR:2007:021 SUSE lists.opensuse.org
APPLE-SA-2009-02-12 Security Update 2009-001 APPLE lists.apple.com
#102705: Security Vulnerabilities (Integer Overflows and a Denial of Service) in the FreeType 2 Font Engine SUNALERT sunsolve.sun.com
Advisories - Mandriva Linux MANDRIVA www.mandriva.com
usn/usn-324-1 - Ubuntu: Linux for human beings UBUNTU www.ubuntu.com
VMware ESX Server 2.0.2 Upgrade Patch 2 (for 2.0.2 Systems) CONFIRM www.vmware.com
Sun Solaris libXfont Integer Overflow Vulnerability - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
Red Hat Customer Portal MISC access.redhat.com
Avaya CMS / IR Sun Solaris libXfont Integer Overflow Vulnerability - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
Webmail - OVH VUPEN www.vupen.com
ASA-2006-176 (RHSA-2006-0500) CONFIRM support.avaya.com
Support REDHAT www.redhat.com Patch, Vendor Advisory
Advisories - Mandriva Linux MANDRIVA www.mandriva.com
VMware ESX Server Multiple Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
Red Hat Customer Portal MISC access.redhat.com
ASA-2006-186 (RHSA-2006-0635) CONFIRM support.avaya.com
VMware ESX Server 2.1.3 Upgrade Patch 2 (for 2.1.3 Systems Only) CONFIRM www.vmware.com
487070 – (CVE-2006-3467) CVE-2006-3467 freetype: integer overflow vulnerability due to incomplete fix for CVE-2006-1861 MISC bugzilla.redhat.com
Red Hat Customer Portal MISC access.redhat.com
VMware ESX Server 2.5.4 Upgrade Patch 1 (for 2.5.4 Systems Only) CONFIRM www.vmware.com
190593 – CVE-2006-1861 freetype multiple integer overflows (CVE-2006-3467) MISC bugzilla.redhat.com
Repository / Oval Repository OVAL oval.cisecurity.org
SecurityFocus BUGTRAQ www.securityfocus.com
Red Hat update for xorg-x11 - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
SGI Advanced Linux Environment Multiple Updates - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
SUSE Updates for Multiple Packages - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
Mandriva update for xorg-x11 - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
Debian update for xfree86 - Secunia Advisories - Vulnerability Intelligence - Secunia.com SECUNIA secunia.com Vendor Advisory
Debian -- Security Information -- DSA-1193-1 xfree86 DEBIAN www.debian.org
Webmail - OVH VUPEN www.vupen.com
Avaya Products FreeType Vulnerabilities - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com SECUNIA secunia.com
usn/usn-341-1 - Ubuntu: Linux for human beings UBUNTU www.ubuntu.com
ASA-2006-284 (SUN 102622, 102677, 102686, 102714, 102719) CONFIRM support.avaya.com
SecurityFocus BUGTRAQ www.securityfocus.com
Security Advisory SA21793 - Ubuntu update for xorg / libxfont - Secunia SECUNIA secunia.com Vendor Advisory
SecurityFocus BUGTRAQ www.securityfocus.com
Webmail - OVH VUPEN www.vupen.com
SecurityFocus BUGTRAQ www.securityfocus.com
Mandriva update for freetype2 - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
20060701-01-U SGI patches.sgi.com
Secunia - Advisories - Ubuntu update for freetype SECUNIA secunia.com Vendor Advisory
Support REDHAT www.redhat.com Vendor Advisory
Secunia - Advisories - SUSE update for freetype2 SECUNIA secunia.com Vendor Advisory
Gentoo Linux Documentation -- LibXfont: Multiple integer overflows GENTOO security.gentoo.org
rPath update for xorg-x11 - Secunia.com SECUNIA secunia.com Vendor Advisory
Red Hat update for freetype - Advisories - Secunia SECUNIA secunia.com
About the security content of Security Update 2009-001 CONFIRM support.apple.com
Gentoo update for libXfont - Secunia Advisories - Vulnerability Intelligence - Secunia.com SECUNIA secunia.com Vendor Advisory
access.redhat.com | CVE-2006-3467 MISC access.redhat.com
Red Hat update for XFree86 - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
Avaya Products XFree86 Vulnerability - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
Trustix updates for freetype / gzip - Advisories - Secunia SECUNIA secunia.com Vendor Advisory
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Vendor Comments And Credit

OrganizationPublishedContributorStatement
Red Hat2007-03-14Mark J CoxRed Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report