5
CVSSv2

CVE-2006-2661

Published: 30/05/2006 Updated: 05/04/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

ftutil.c in Freetype prior to 2.2 allows remote malicious users to cause a denial of service (crash) via a crafted font file that triggers a null dereference.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freetype freetype

debian debian linux 3.0

debian debian linux 3.1

canonical ubuntu linux 5.04

canonical ubuntu linux 5.10

canonical ubuntu linux 6.06

Vendor Advisories

Several integer overflows have been discovered in the FreeType library By tricking a user into installing and/or opening a specially crafted font file, these could be exploited to execute arbitrary code with the privileges of that user ...
Several problems have been discovered in the FreeType 2 font engine The Common vulnerabilities and Exposures project identifies the following problems: CVE-2006-0747 Several integer underflows have been discovered which could allow remote attackers to cause a denial of service CVE-2006-1861 Chris Evans discovered several integer over ...

Exploits

source: wwwsecurityfocuscom/bid/18329/info FreeType is prone to a denial-of-service vulnerability This issue is due to a flaw in the library that causes a NULL-pointer dereference This issue allows remote attackers to crash applications that use the affected library, denying service to legitimate users FreeType versions prior to 22 ...