Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-10244

Опубликовано: 06 мар. 2017
Источник: debian

Описание

The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
freetypefixed2.7.1-0.1experimentalpackage
freetypefixed2.6.3-3.1package

Примечания

  • Fixed in 2.7: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/tree/ChangeLog?h=VER-2-7

  • https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=36

  • Fixed by: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=a660e3de422731b94d4a134d27555430cbb6fb39 (VER-2-7)

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 9 лет назад

The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file.

CVSS3: 5.9
redhat
больше 9 лет назад

The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file.

CVSS3: 7.8
nvd
почти 9 лет назад

The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file.

CVSS3: 7.8
github
больше 3 лет назад

The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file.

fstec
почти 9 лет назад

Уязвимость библиотеки FreeType, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие