Executive Summary
Summary | |
---|---|
Title | NX 2.1: User-assisted execution of arbitrary code |
Informations | |||
---|---|---|---|
Name | GLSA-200710-09 | First vendor Publication | 2007-10-09 |
Vendor | Gentoo | Last vendor Modification | 2007-10-09 |
Severity (Vendor) | Normal | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Synopsis NX in the 2.1 series uses XFree86 4.3 code which is prone to an integer overflow vulnerability. Background Description Impact Workaround Resolution All NX Node users should upgrade to the latest version: References Availability http://security.gentoo.org/glsa/glsa-200710-09.xml |
Original Source
Url : http://security.gentoo.org/glsa/glsa-200710-09.xml |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-189 | Numeric Errors (CWE/SANS Top 25) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:9124 | |||
Oval ID: | oval:org.mitre.oval:def:9124 | ||
Title: | Multiple integer overflows in FreeType before 2.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to (1) bdf/bdflib.c, (2) sfnt/ttcmap.c, (3) cff/cffgload.c, and (4) the read_lwfn function and a crafted LWFN file in base/ftmac.c. NOTE: item 4 was originally identified by CVE-2006-2493. | ||
Description: | Multiple integer overflows in FreeType before 2.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to (1) bdf/bdflib.c, (2) sfnt/ttcmap.c, (3) cff/cffgload.c, and (4) the read_lwfn function and a crafted LWFN file in base/ftmac.c. NOTE: item 4 was originally identified by CVE-2006-2493. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2006-1861 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2011-08-09 | Name : CentOS Update for freetype CESA-2009:0329 centos3 i386 File : nvt/gb_CESA-2009_0329_freetype_centos3_i386.nasl |
2011-03-09 | Name : Gentoo Security Advisory GLSA 201006-01 (freetype) File : nvt/glsa_201006_01.nasl |
2010-05-12 | Name : Mac OS X Security Update 2009-001 File : nvt/macosx_secupd_2009-001.nasl |
2009-06-05 | Name : Fedora Core 10 FEDORA-2009-5558 (freetype1) File : nvt/fcore_2009_5558.nasl |
2009-06-05 | Name : Fedora Core 11 FEDORA-2009-5644 (freetype1) File : nvt/fcore_2009_5644.nasl |
2009-05-25 | Name : RedHat Security Advisory RHSA-2009:0329 File : nvt/RHSA_2009_0329.nasl |
2009-05-25 | Name : RedHat Security Advisory RHSA-2009:1062 File : nvt/RHSA_2009_1062.nasl |
2009-05-25 | Name : CentOS Security Advisory CESA-2009:0329 (freetype) File : nvt/ovcesa2009_0329.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200607-02 (FreeType) File : nvt/glsa_200607_02.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200710-09 (nx, nxnode) File : nvt/glsa_200710_09.nasl |
2008-09-04 | Name : FreeBSD Ports: freetype2 File : nvt/freebsd_freetype2.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 1095-1 (freetype) File : nvt/deb_1095_1.nasl |
0000-00-00 | Name : Slackware Advisory SSA:2006-207-02 x11 File : nvt/esoft_slk_ssa_2006_207_02.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
41726 | FreeType cff/cffgload.c Unspecified Overflow |
41725 | FreeType sfnt/ttcmap.c Unspecified Overflow |
41724 | FreeType bdf/bdflib.c Unspecified Overflow |
25654 | FreeType base/ftmac.c read_lwfn() Function LWFN File Handling Overflow |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2009-0329.nasl - Type : ACT_GATHER_INFO |
2012-08-01 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20090522_freetype_on_SL3_x.nasl - Type : ACT_GATHER_INFO |
2010-06-02 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201006-01.nasl - Type : ACT_GATHER_INFO |
2009-05-28 | Name : The remote Fedora host is missing a security update. File : fedora_2009-5558.nasl - Type : ACT_GATHER_INFO |
2009-05-28 | Name : The remote Fedora host is missing a security update. File : fedora_2009-5644.nasl - Type : ACT_GATHER_INFO |
2009-05-23 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2009-0329.nasl - Type : ACT_GATHER_INFO |
2009-05-23 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2009-1062.nasl - Type : ACT_GATHER_INFO |
2009-05-23 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2009-0329.nasl - Type : ACT_GATHER_INFO |
2009-02-13 | Name : The remote host is missing a Mac OS X update that fixes various security issues. File : macosx_SecUpd2009-001.nasl - Type : ACT_GATHER_INFO |
2007-11-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-291-1.nasl - Type : ACT_GATHER_INFO |
2007-10-18 | Name : The remote openSUSE host is missing a security update. File : suse_NX-4555.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_freetype2-1608.nasl - Type : ACT_GATHER_INFO |
2007-10-12 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200710-09.nasl - Type : ACT_GATHER_INFO |
2006-12-16 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2006-129.nasl - Type : ACT_GATHER_INFO |
2006-10-14 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1095.nasl - Type : ACT_GATHER_INFO |
2006-10-05 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_b975763f521011db8f1a000a48049292.nasl - Type : ACT_GATHER_INFO |
2006-07-28 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2006-207-02.nasl - Type : ACT_GATHER_INFO |
2006-07-19 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2006-0500.nasl - Type : ACT_GATHER_INFO |
2006-07-19 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2006-0500.nasl - Type : ACT_GATHER_INFO |
2006-07-10 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200607-02.nasl - Type : ACT_GATHER_INFO |
2006-06-16 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2006-099.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:35:10 |
|