Vulnerability CVE-2010-2519: Information

Description

Heap-based buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted length value in a POST fragment header in a font file.

Severity: MEDIUM (6.8)

Published: Aug. 19, 2010
Modified: Feb. 13, 2023
Error type identifier: CWE-787

References to Advisories, Solutions, and Tools

Hyperlink
Resource
[oss-security] 20100713 Multiple bugs in freetype
  • Mailing List
  • Third Party Advisory
USN-963-1
  • Third Party Advisory
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=b2ea64bcc6c385a8e8318f9c759450a07df58b6d
  • Patch
  • Third Party Advisory
DSA-2070
  • Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=613194
  • Issue Tracking
  • Patch
  • Third Party Advisory
[oss-security] 20100714 Re: Multiple bugs in freetype
  • Mailing List
  • Third Party Advisory
MDVSA-2010:137
  • Third Party Advisory
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=5ef20c8c1d4de12a84b50ba497c2a358c90ec44b
  • Patch
  • Third Party Advisory
https://savannah.nongnu.org/bugs/?30306
  • Exploit
  • Issue Tracking
  • Third Party Advisory
[freetype] 20100712 FreeType 2.4.0 has been released
  • Mailing List
  • Release Notes
  • Third Party Advisory
RHSA-2010:0578
  • Third Party Advisory
1024266
  • Third Party Advisory
  • VDB Entry
http://support.apple.com/kb/HT4435
  • Broken Link
APPLE-SA-2010-11-10-1
  • Mailing List
  • Third Party Advisory
48951
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*
      End excliding
      2.4.0

      Configuration 2

      cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
      End excliding
      10.6.5

      Configuration 4

      cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*