6.8

CVE-2010-2806

Exploit

Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via negative size values for certain strings in FontType42 font files, leading to a heap-based buffer overflow.

Data is provided by the National Vulnerability Database (NVD)
FreetypeFreetype Version < 2.4.2
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version8.04 SwEdition-
CanonicalUbuntu Linux Version9.04
CanonicalUbuntu Linux Version9.10
CanonicalUbuntu Linux Version10.04 SwEdition-
AppleiPhone OS Version < 4.2
ApplemacOS X Version < 10.6.5
AppletvOS Version < 4.1.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 9.38% 0.92
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-129 Improper Validation of Array Index

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

https://bugs.launchpad.net/ubuntu/maverick/+source/freetype/+bug/617019
Third Party Advisory
Release Notes
Issue Tracking
http://marc.info/?l=oss-security&m=128111955616772&w=2
Patch
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/42285
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=621980
Patch
Third Party Advisory
Issue Tracking
https://savannah.nongnu.org/bugs/?30656
Third Party Advisory
Exploit