Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-1797

Опубликовано: 16 авг. 2010
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 9.3

Описание

Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted CFF opcodes in embedded fonts in a PDF document, as demonstrated by JailbreakMe. NOTE: some of these details are obtained from third party information.

РелизСтатусПримечание
dapper

released

2.1.10-1ubuntu2.8
devel

not-affected

2.4.2-1
hardy

released

2.3.5-1ubuntu4.8.04.4
jaunty

released

2.3.9-4ubuntu0.3
karmic

released

2.3.9-5ubuntu0.2
lucid

released

2.3.11-1ubuntu2.2
upstream

released

2.4.2

Показывать по

EPSS

Процентиль: 97%
0.38534
Средний

9.3 Critical

CVSS2

Связанные уязвимости

redhat
почти 15 лет назад

Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted CFF opcodes in embedded fonts in a PDF document, as demonstrated by JailbreakMe. NOTE: some of these details are obtained from third party information.

nvd
почти 15 лет назад

Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted CFF opcodes in embedded fonts in a PDF document, as demonstrated by JailbreakMe. NOTE: some of these details are obtained from third party information.

debian
почти 15 лет назад

Multiple stack-based buffer overflows in the cff_decoder_parse_charstr ...

github
около 3 лет назад

Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted CFF opcodes in embedded fonts in a PDF document, as demonstrated by JailbreakMe. NOTE: some of these details are obtained from third party information.

oracle-oval
почти 15 лет назад

ELSA-2010-0607: freetype security update (IMPORTANT)

EPSS

Процентиль: 97%
0.38534
Средний

9.3 Critical

CVSS2