Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-2520

Опубликовано: 09 июн. 2010
Источник: redhat
CVSS2: 7.5

Описание

Heap-based buffer overflow in the Ins_IUP function in truetype/ttinterp.c in FreeType before 2.4.0, when TrueType bytecode support is enabled, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.

Отчет

Not vulnerable. This issue did not affect the versions of freetype as shipped with Red Hat Enterprise Linux 3, 4, or 5.

Дополнительная информация

Статус:

Important
Дефект:
CWE-228->CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=613198freetype: heap buffer overflow vulnerability in truetype bytecode support

7.5 High

CVSS2

Связанные уязвимости

ubuntu
больше 15 лет назад

Heap-based buffer overflow in the Ins_IUP function in truetype/ttinterp.c in FreeType before 2.4.0, when TrueType bytecode support is enabled, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.

nvd
больше 15 лет назад

Heap-based buffer overflow in the Ins_IUP function in truetype/ttinterp.c in FreeType before 2.4.0, when TrueType bytecode support is enabled, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.

debian
больше 15 лет назад

Heap-based buffer overflow in the Ins_IUP function in truetype/ttinter ...

github
больше 3 лет назад

Heap-based buffer overflow in the Ins_IUP function in truetype/ttinterp.c in FreeType before 2.4.0, when TrueType bytecode support is enabled, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.

fstec
около 14 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

7.5 High

CVSS2

Уязвимость CVE-2010-2520