>> X.Org X11 "CIDAFM()" and "scan_cidfont()" Local Privilege Escalation Vulnerabilities
Title : X.Org X11 "CIDAFM()" and "scan_cidfont()" Local Privilege Escalation Vulnerabilities VUPEN ID : VUPEN/ADV-2006-3581 CVE ID : CVE-2006-3739 - CVE-2006-3740
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-09-13
Technical Description
Two vulnerabilities have been identified in X.Org X11, which could be exploited by malicious users to obtain elevated privileges or cause a denial of service.
The first issue is due to an integer overflow error in the "CIDAFM()" [Type1/afm.c] function when processing AFM (Adobe Font Metrics) files, which could be exploited by local attackers to execute arbitrary commands with root privileges.
The second flaw is due to an integer overflow error in the "scan_cidfont()" [Type1/scanfont.c] function when processing malformed "CMap" and "CIDFont" font data, which could be exploited by local attackers to execute arbitrary commands with root privileges.