5

CVE-2006-2661

ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FreetypeFreetype Version < 2.2
DebianDebian Linux Version3.0
DebianDebian Linux Version3.1
CanonicalUbuntu Linux Version5.04
CanonicalUbuntu Linux Version5.10
CanonicalUbuntu Linux Version6.06 SwEditionlts
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 12.64% 0.936
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=183676
Patch
Third Party Advisory
Issue Tracking
https://usn.ubuntu.com/291-1/
Third Party Advisory
http://securitytracker.com/id?1016520
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/18329
Third Party Advisory
VDB Entry