CVE-2006-3467

Publication date 21 July 2006

Last updated 17 July 2025


Ubuntu priority

Integer overflow in FreeType before 2.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PCF file, as demonstrated by the Red Hat bad1.pcf test file, due to a partial fix of CVE-2006-1861.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
xorg 9.10 karmic
Not affected
9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected
freetype 9.10 karmic
Fixed 2.3.5-1ubuntu1
9.04 jaunty
Fixed 2.3.5-1ubuntu1
8.10 intrepid
Fixed 2.3.5-1ubuntu1
8.04 LTS hardy
Fixed 2.3.5-1ubuntu1
7.10 gutsy
Fixed 2.3.5-1ubuntu1
7.04 feisty
Fixed 2.2.1-5ubuntu1.1
6.10 edgy
Fixed 2.2.1-5ubuntu0.2
6.06 LTS dapper
Fixed 2.1.10-1ubuntu2.4
libxfont 9.10 karmic
Fixed 1.2.7-1ubuntu1
9.04 jaunty
Fixed 1.2.7-1ubuntu1
8.10 intrepid
Fixed 1.2.7-1ubuntu1
8.04 LTS hardy
Fixed 1.2.7-1ubuntu1
7.10 gutsy
Fixed 1.2.7-1ubuntu1
7.04 feisty
Fixed 1.2.7-1ubuntu1
6.10 edgy
Fixed 1.2.0-0ubuntu3.1
6.06 LTS dapper
Fixed 1.0.0-0ubuntu3.3
ia32-libs 9.10 karmic
Not affected
9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy Ignored end of life, was needed
7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Fixed 1.4ubuntu20

References

Related Ubuntu Security Notices (USN)

    • USN-341-1
    • libxfont vulnerability
    • 7 September 2006
    • USN-324-1
    • freetype vulnerability
    • 28 July 2006

Other references