PT-2010-1118 · Freetype+1 · Freetype+1

Publicado

2010-08-19

·

Atualizado

2024-06-15

·

CVE-2010-3053

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FreeType versions prior to 2.4.2 FreeType versions prior to 2.4.8
Description The issue allows remote attackers to cause problems with the application, potentially leading to a denial of service, by using a specially crafted BDF font file. This is related to an attempted modification of a value in a static string. Multiple vulnerabilities in the FreeType package can lead to issues with confidentiality, integrity, and availability of protected information, and these can be exploited remotely.
Recommendations For versions prior to 2.4.2, update to version 2.4.2 or later. For versions prior to 2.4.8, update to version 2.4.8 or later.

Correção

DoS

Buffer Overflow

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09431
CVE-2010-3053
DSA-2105-1
OPENSUSE-SU-2024:10172-1
OPENSUSE-SU-2024:10438-1

Produtos afetados

Freetype
Suse