CVE-2006-2661: Null Pointer Dereference
Published May 30, 2006
·Updated
ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference.
Affected Software
6 affected components
FreeType FreeType<2.2
Debian Debian Linux=3.1
Debian Debian Linux=3.0
Canonical Ubuntu Linux=5.04
Canonical Ubuntu Linux=6.06
Canonical Ubuntu Linux=5.10
Remediation
Patch Available
Event History
May 30, 2006
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2661?
CVE-2006-2661 is classified as a medium-severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2006-2661?
To fix CVE-2006-2661, update FreeType to version 2.2 or later, or apply any available patches from your distribution.
3
What are the potential consequences of CVE-2006-2661?
The potential consequences of CVE-2006-2661 include system crashes and disruption of services due to denial of service.
4
Which software versions are affected by CVE-2006-2661?
CVE-2006-2661 affects FreeType versions prior to 2.2 and specific versions of Debian and Ubuntu Linux.
5
Is there a public exploit for CVE-2006-2661?
While there is no widely known public exploit for CVE-2006-2661, the vulnerability can be triggered by specially crafted font files.