Vulnerability CVE-2010-2498: Information

Description

The psh_glyph_find_strong_points function in pshinter/pshalgo.c in FreeType before 2.4.0 does not properly implement hinting masks, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted font file that triggers an invalid free operation.

Severity: MEDIUM (6.8)

Published: Aug. 19, 2010
Modified: April 6, 2021
Error type identifier: CWE-787

References to Advisories, Solutions, and Tools

Hyperlink
Resource
DSA-2070
  • Third Party Advisory
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=8d22746c9e5af80ff4304aef440986403a5072e2
  • Patch
  • Third Party Advisory
[oss-security] 20100714 Re: Multiple bugs in freetype
  • Mailing List
  • Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=613160
  • Issue Tracking
  • Patch
  • Third Party Advisory
https://savannah.nongnu.org/bugs/?30106
  • Exploit
  • Issue Tracking
  • Third Party Advisory
RHSA-2010:0578
  • Third Party Advisory
USN-963-1
  • Third Party Advisory
[oss-security] 20100713 Multiple bugs in freetype
  • Mailing List
  • Third Party Advisory
1024266
  • Third Party Advisory
  • VDB Entry
MDVSA-2010:137
  • Third Party Advisory
[freetype] 20100712 FreeType 2.4.0 has been released
  • Mailing List
  • Release Notes
  • Third Party Advisory
APPLE-SA-2010-11-10-1
  • Mailing List
  • Third Party Advisory
http://support.apple.com/kb/HT4435
  • Broken Link
48951
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*
      End excliding
      2.4.0

      Configuration 2

      cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
      End excliding
      10.6.5

      Configuration 4

      cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*