PT-2010-1118 · Freetype+1 · Freetype+1
Published
2010-08-19
·
Updated
2024-06-15
·
CVE-2010-3053
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FreeType versions prior to 2.4.2
FreeType versions prior to 2.4.8
Description
The issue allows remote attackers to cause problems with the application, potentially leading to a denial of service, by using a specially crafted BDF font file. This is related to an attempted modification of a value in a static string. Multiple vulnerabilities in the FreeType package can lead to issues with confidentiality, integrity, and availability of protected information, and these can be exploited remotely.
Recommendations
For versions prior to 2.4.2, update to version 2.4.2 or later.
For versions prior to 2.4.8, update to version 2.4.8 or later.
Fix
DoS
Buffer Overflow
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freetype
Suse