First published: Wed Sep 13 2006(Updated: )
Integer overflow in the CIDAFM function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted Adobe Font Metrics (AFM) files with a modified number of character metrics (StartCharMetrics), which leads to a heap-based buffer overflow.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
XFree86 | ||
X Server (X.Org) | =6.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3739 has a high severity rating due to the potential for local users to execute arbitrary code.
To fix CVE-2006-3739, upgrade to a patched version of X.Org or XFree86 that addresses the integer overflow vulnerability.
CVE-2006-3739 affects X.Org version 6.8.2 and XFree86 X Server.
Local users can exploit CVE-2006-3739 by crafting Adobe Font Metrics (AFM) files.
The attack vector for CVE-2006-3739 involves creating malicious AFM files that trigger a heap-based buffer overflow.