FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-1861

This CVE name corresponds to:

Entered Topic
2006-10-02 freetype -- LWFN Files Buffer Overflow Vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-1861
Phase Assigned(20060419)

Description

Multiple integer overflows in FreeType before 2.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to (1) bdf/bdflib.c, (2) sfnt/ttcmap.c, (3) cff/cffgload.c, and (4) the read_lwfn function and a crafted LWFN file in base/ftmac.c. NOTE: item 4 was originally identified by CVE-2006-2493.

References

Source Reference
BUGTRAQ 20060612 rPSA-2006-0100-1 freetype
CONFIRM http://sourceforge.net/project/shownotes.php?release_id=416463
CONFIRM https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=190593
CONFIRM https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=190593#c8
CONFIRM https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=128606
CONFIRM https://issues.rpath.com/browse/RPL-429
CONFIRM http://support.avaya.com/elmodocs2/security/ASA-2006-176.htm
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=502565
CONFIRM http://support.apple.com/kb/HT3438
APPLE APPLE-SA-2009-02-12
DEBIAN DSA-1095
FEDORA FEDORA-2009-5558
FEDORA FEDORA-2009-5644
GENTOO GLSA-200607-02
GENTOO GLSA-200710-09
MANDRIVA MDKSA-2006:099
REDHAT RHSA-2006:0500
REDHAT RHSA-2009:0329
REDHAT RHSA-2009:1062
SGI 20060701-01-U
SUNALERT 102705
SUSE SUSE-SA:2006:037
SUSE SUSE-SR:2007:021
UBUNTU USN-291-1
BID 18034
OVAL oval:org.mitre.oval:def:9124
SECUNIA 35200
SECUNIA 35204
SECUNIA 35233
VUPEN ADV-2006-1868
VUPEN ADV-2007-0381
SECTRACK 1016522
SECUNIA 20100
SECUNIA 20525
SECUNIA 20591
SECUNIA 20638
SECUNIA 20791
SECUNIA 21000
SECUNIA 21062
SECUNIA 21135
SECUNIA 21385
SECUNIA 21701
SECUNIA 23939
SECUNIA 27162
SECUNIA 27167
SECUNIA 27271
SECUNIA 33937
XF freetype-lwfn-overflow(26553)