CVE-2006-3740
Summary
| CVE | CVE-2006-3740 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-09-13 01:07:00 UTC |
| Updated | 2018-10-17 21:29:00 UTC |
| Description | Integer overflow in the scan_cidfont function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted (1) CMap and (2) CIDFont font data with modified item counts in the (a) begincodespacerange, (b) cidrange, and (c) notdefrange sections. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | X.org | X.org | 6.8.2 | All | All | All |
| Application | X.org | X.org | 6.8.2 | All | All | All |
| Application | Xfree86 Project | Xfree86 X | All | All | All | All |
| Application | Xfree86 Project | Xfree86 X | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail - OVH | VUPEN | www.vupen.com | |
| usn/usn-344-1 - Ubuntu: Linux for human beings | UBUNTU | www.ubuntu.com | |
| VMware ESX Server 2.5.4 Upgrade Patch 5 (for 2.5.4 Systems Only) | CONFIRM | www.vmware.com | |
| X11 libXfont CID Encoded Fonts Integer Overflows - Advisories - Secunia | SECUNIA | secunia.com | |
| Mandriva update for xorg-x11 - Advisories - Secunia | SECUNIA | secunia.com | |
| #102780: Two Integer Overflow Vulnerabilities Found in the Xorg(1) X Server | SUNALERT | sunsolve.sun.com | |
| X.Org LibXfont CID Font File Multiple Integer Overflow Vulnerabilities | BID | www.securityfocus.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| Avaya Modular Messaging X11 libXfont Integer Overflows - Advisories - Secunia | SECUNIA | secunia.com | |
| SUSE Update for Multiple Packages - Advisories - Secunia | SECUNIA | secunia.com | |
| Accenture | Let there be change | IDEFENSE | www.idefense.com | Patch, Vendor Advisory |
| Ubuntu updates for libxfont / xorg - Advisories - Secunia | SECUNIA | secunia.com | |
| Red Hat update for XFree86 - Advisories - Secunia | SECUNIA | secunia.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Security Announcement | SUSE | www.novell.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | Patch, Vendor Advisory |
| [#RPL-614] local root privilege escalation vulnerabilities in CID fonts parser: CVE-2006-3739 CVE-2006-3740 - rPath JIRA | CONFIRM | issues.rpath.com | |
| rPath update for xorg-x11 - Advisories - Secunia | SECUNIA | secunia.com | |
| Red Hat update for xorg-x11 - Advisories - Secunia | SECUNIA | secunia.com | |
| XFree86 CID Encoded Fonts Integer Overflows - Advisories - Secunia | SECUNIA | secunia.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| Gentoo Linux Documentation -- LibXfont, monolithic X.org: Multiple integer overflows | GENTOO | security.gentoo.org | |
| Debian update for xfree86 - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | |
| Debian -- Security Information -- DSA-1193-1 xfree86 | DEBIAN | www.debian.org | |
| Sun Solaris 10 Xorg X Server Integer Overflows - Advisories - Secunia | SECUNIA | secunia.com | |
| ASA-2006-190 (RHSA-2006-0665) | CONFIRM | support.avaya.com | |
| Support | REDHAT | www.redhat.com | Patch, Vendor Advisory |
| Sun Solaris 9 Xorg X Server Integer Overflows - Advisories - Secunia | SECUNIA | secunia.com | |
| VMware ESX Server Multiple Security Updates - Advisories - Secunia | SECUNIA | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Mandriva update for xorg-x11 - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | |
| SecurityTracker.com Archives - X Buffer Overflow in Processing CID-encoded Type1 Fonts Lets Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| Gentoo update for libXfont - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | |
| ASA-2006-191 (RHSA-2006-0666) | CONFIRM | support.avaya.com | |
| Avaya Products XFree86 Integer Overflow Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.