PT-2010-1118 · Freetype+1 · Freetype+1

Published

2010-08-19

·

Updated

2024-06-15

·

CVE-2010-3053

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FreeType versions prior to 2.4.2 FreeType versions prior to 2.4.8
Description The issue allows remote attackers to cause problems with the application, potentially leading to a denial of service, by using a specially crafted BDF font file. This is related to an attempted modification of a value in a static string. Multiple vulnerabilities in the FreeType package can lead to issues with confidentiality, integrity, and availability of protected information, and these can be exploited remotely.
Recommendations For versions prior to 2.4.2, update to version 2.4.2 or later. For versions prior to 2.4.8, update to version 2.4.8 or later.

Fix

DoS

Buffer Overflow

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09431
CVE-2010-3053
DSA-2105-1
OPENSUSE-SU-2024:10172-1
OPENSUSE-SU-2024:10438-1

Affected Products

Freetype
Suse