5
CVSSv2

CVE-2006-0747

Published: 23/05/2006 Updated: 19/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Integer underflow in Freetype prior to 2.2 allows remote malicious users to cause a denial of service (crash) via a font file with an odd number of blue values, which causes the underflow when decrementing by 2 in a context that assumes an even number of values.

Vulnerable Product Search on Vulmon Subscribe to Product

freetype freetype

Vendor Advisories

Several integer overflows have been discovered in the FreeType library By tricking a user into installing and/or opening a specially crafted font file, these could be exploited to execute arbitrary code with the privileges of that user ...
Several problems have been discovered in the FreeType 2 font engine The Common vulnerabilities and Exposures project identifies the following problems: CVE-2006-0747 Several integer underflows have been discovered which could allow remote attackers to cause a denial of service CVE-2006-1861 Chris Evans discovered several integer over ...

Exploits

source: wwwsecurityfocuscom/bid/18326/info FreeType is prone to a buffer-overflow vulnerability This issue is due to an integer-underflow that results in a buffer being overrun with attacker-supplied data This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library F ...