PT-2007-7538 · Freetype+1 · Freetype2-32Bit+5

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2007-2754

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Freetype versions prior to 2.3.4 Freetype-devel versions 2.0.3 Freetype-utils versions 2.0.3 Freetype2 versions (affected versions not specified) Freetype2-32bit versions (affected versions not specified)
Description The issue is related to multiple vulnerabilities in the Freetype package, which can lead to disruption of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be done remotely. Specifically, an integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n points value, leading to an integer overflow and heap-based buffer overflow.
Recommendations For Freetype versions prior to 2.3.4, update to version 2.3.4 or later. For Freetype-devel versions 2.0.3, update to a version later than 2.0.3. For Freetype-utils versions 2.0.3, update to a version later than 2.0.3. For Freetype2 and Freetype2-32bit, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2015-04969
BDU:2015-04970
BDU:2015-06175
BDU:2015-06177
BDU:2015-06179
BDU:2015-09401
BDU:2015-09578
CVE-2007-2754
DSA-1302-1
DSA-1334-1
RHSA-2007:0403
RHSA-2007_0403
RHSA-2009:0329
RHSA-2009:1062
RHSA-2009_0329

Affected Products

Freetype
Freetype-Devel
Freetype-Utils
Freetype2
Freetype2-32Bit
Red Hat