Vulnerability CVE-2010-2519: Information
Description
Heap-based buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted length value in a POST fragment header in a font file.
Severity: MEDIUM (6.8)
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
[oss-security] 20100713 Multiple bugs in freetype |
|
USN-963-1 |
|
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=b2ea64bcc6c385a8e8318f9c759450a07df58b6d |
|
DSA-2070 |
|
https://bugzilla.redhat.com/show_bug.cgi?id=613194 |
|
[oss-security] 20100714 Re: Multiple bugs in freetype |
|
MDVSA-2010:137 |
|
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=5ef20c8c1d4de12a84b50ba497c2a358c90ec44b |
|
https://savannah.nongnu.org/bugs/?30306 |
|
[freetype] 20100712 FreeType 2.4.0 has been released |
|
RHSA-2010:0578 |
|
1024266 |
|
http://support.apple.com/kb/HT4435 |
|
APPLE-SA-2010-11-10-1 |
|
48951 |
|