Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-10244

Опубликовано: 06 мар. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8
CVSS3: 7.8

Описание

The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file.

РелизСтатусПримечание
devel

released

2.6.3-3ubuntu2
esm-infra-legacy/trusty

released

2.5.2-1ubuntu2.6
esm-infra/xenial

released

2.6.1-0.1ubuntu2.1
precise

released

2.4.8-1ubuntu2.4
precise/esm

not-affected

2.4.8-1ubuntu2.4
trusty

released

2.5.2-1ubuntu2.6
trusty/esm

released

2.5.2-1ubuntu2.6
upstream

released

2.7
vivid/stable-phone-overlay

ignored

end of life
vivid/ubuntu-core

released

2.5.2-2ubuntu3.2

Показывать по

EPSS

Процентиль: 56%
0.00334
Низкий

6.8 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 5.9
redhat
больше 9 лет назад

The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file.

CVSS3: 7.8
nvd
почти 9 лет назад

The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file.

CVSS3: 7.8
debian
почти 9 лет назад

The parse_charstrings function in type1/t1load.c in FreeType 2 before ...

CVSS3: 7.8
github
больше 3 лет назад

The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file.

fstec
почти 9 лет назад

Уязвимость библиотеки FreeType, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие

EPSS

Процентиль: 56%
0.00334
Низкий

6.8 Medium

CVSS2

7.8 High

CVSS3