« List of all CVEs

CVE-2006-1861

Published: 5/23/2006 Last updated: 8/7/2024 Reserved: 4/19/2006

Multiple integer overflows in FreeType before 2.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to (1) bdf/bdflib.c, (2) sfnt/ttcmap.c, (3) cff/cffgload.c, and (4) the read_lwfn function and a crafted LWFN file in base/ftmac.c. NOTE: item 4 was originally identified by CVE-2006-2493.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (2)

conf-freetype conf-gd

Products affected (1)

Product Vendor Version
n/a n/a < 2023.1.6

References (96)