Vulnerability CVE-2010-2498: Information
Description
The psh_glyph_find_strong_points function in pshinter/pshalgo.c in FreeType before 2.4.0 does not properly implement hinting masks, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted font file that triggers an invalid free operation.
Severity: MEDIUM (6.8)
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
DSA-2070 |
|
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=8d22746c9e5af80ff4304aef440986403a5072e2 |
|
[oss-security] 20100714 Re: Multiple bugs in freetype |
|
https://bugzilla.redhat.com/show_bug.cgi?id=613160 |
|
https://savannah.nongnu.org/bugs/?30106 |
|
RHSA-2010:0578 |
|
USN-963-1 |
|
[oss-security] 20100713 Multiple bugs in freetype |
|
1024266 |
|
MDVSA-2010:137 |
|
[freetype] 20100712 FreeType 2.4.0 has been released |
|
APPLE-SA-2010-11-10-1 |
|
http://support.apple.com/kb/HT4435 |
|
48951 |
|