CVE-2006-3467

Publication date 21 July 2006

Last updated 24 July 2024


Ubuntu priority

Integer overflow in FreeType before 2.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PCF file, as demonstrated by the Red Hat bad1.pcf test file, due to a partial fix of CVE-2006-1861.

Status

Package Ubuntu Release Status
freetype 9.10 karmic
Fixed 2.3.5-1ubuntu1
9.04 jaunty
Fixed 2.3.5-1ubuntu1
8.10 intrepid
Fixed 2.3.5-1ubuntu1
8.04 LTS hardy
Fixed 2.3.5-1ubuntu1
7.10 gutsy
Fixed 2.3.5-1ubuntu1
7.04 feisty
Fixed 2.2.1-5ubuntu1.1
6.10 edgy
Fixed 2.2.1-5ubuntu0.2
6.06 LTS dapper
Fixed 2.1.10-1ubuntu2.4
ia32-libs 9.10 karmic
Not affected
9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy Ignored end of life, was needed
7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Fixed 1.4ubuntu20
libxfont 9.10 karmic
Fixed 1.2.7-1ubuntu1
9.04 jaunty
Fixed 1.2.7-1ubuntu1
8.10 intrepid
Fixed 1.2.7-1ubuntu1
8.04 LTS hardy
Fixed 1.2.7-1ubuntu1
7.10 gutsy
Fixed 1.2.7-1ubuntu1
7.04 feisty
Fixed 1.2.7-1ubuntu1
6.10 edgy
Fixed 1.2.0-0ubuntu3.1
6.06 LTS dapper
Fixed 1.0.0-0ubuntu3.3
xorg 9.10 karmic
Not affected
9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected

References

Related Ubuntu Security Notices (USN)

    • USN-341-1
    • libxfont vulnerability
    • 7 September 2006
    • USN-324-1
    • freetype vulnerability
    • 28 July 2006

Other references