CVE-2006-3739: Buffer Overflow
Integer overflow in the CIDAFM function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted Adobe Font Metrics (AFM) files with a modified number of character metrics (StartCharMetrics), which leads to a heap-based buffer overflow.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3739?
CVE-2006-3739 has a high severity rating due to the potential for local users to execute arbitrary code.
How do I fix CVE-2006-3739?
To fix CVE-2006-3739, upgrade to a patched version of X.Org or XFree86 that addresses the integer overflow vulnerability.
Which software versions are affected by CVE-2006-3739?
CVE-2006-3739 affects X.Org version 6.8.2 and XFree86 X Server.
Who can exploit CVE-2006-3739?
Local users can exploit CVE-2006-3739 by crafting Adobe Font Metrics (AFM) files.
What is the attack vector for CVE-2006-3739?
The attack vector for CVE-2006-3739 involves creating malicious AFM files that trigger a heap-based buffer overflow.