5

CVE-2006-2661

ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FreetypeFreetype Version < 2.2
DebianDebian Linux Version3.0
DebianDebian Linux Version3.1
CanonicalUbuntu Linux Version5.04
CanonicalUbuntu Linux Version5.10
CanonicalUbuntu Linux Version6.06 SwEditionlts
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.35% 0.928
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=183676
Patch
Third Party Advisory
Issue Tracking
https://usn.ubuntu.com/291-1/
Third Party Advisory
http://securitytracker.com/id?1016520
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/18329
Third Party Advisory
VDB Entry