CVE-2010-1797

Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted CFF opcodes in embedded fonts in a PDF document, as demonstrated by JailbreakMe. NOTE: some of these details are obtained from third party information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
appleCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
appleiphone_os
1.0.0
appleiphone_os
1.0.1
appleiphone_os
1.0.1
appleiphone_os
1.0.2
appleiphone_os
1.0.2
appleiphone_os
1.1.0
appleiphone_os
1.1.0
appleiphone_os
1.1.0
appleiphone_os
1.1.1
appleiphone_os
1.1.1
appleiphone_os
1.1.2
appleiphone_os
1.1.2
appleiphone_os
1.1.2
appleiphone_os
1.1.3
appleiphone_os
1.1.3
appleiphone_os
1.1.3
appleiphone_os
1.1.4
appleiphone_os
1.1.4
appleiphone_os
1.1.4
appleiphone_os
1.1.5
appleiphone_os
1.1.5
appleiphone_os
1.1.5
appleiphone_os
2.0
appleiphone_os
2.0.0
appleiphone_os
2.0.0
appleiphone_os
2.0.0
appleiphone_os
2.0.1
appleiphone_os
2.0.1
appleiphone_os
2.0.1
appleiphone_os
2.0.2
appleiphone_os
2.0.2
appleiphone_os
2.0.2
appleiphone_os
2.1
appleiphone_os
2.1
appleiphone_os
2.1
appleiphone_os
2.1.1
appleiphone_os
2.2
appleiphone_os
2.2
appleiphone_os
2.2.1
appleiphone_os
2.2.1
appleiphone_os
2.2.1
appleiphone_os
3.0
appleiphone_os
3.0
appleiphone_os
3.0
appleiphone_os
3.0.1
appleiphone_os
3.0.1
appleiphone_os
3.1
appleiphone_os
3.1
appleiphone_os
3.1
appleiphone_os
3.1.2
appleiphone_os
3.1.2
appleiphone_os
3.1.2
appleiphone_os
3.1.3
appleiphone_os
3.1.3
appleiphone_os
3.2
appleiphone_os
3.2
appleiphone_os
3.2
appleiphone_os
3.2.1
appleiphone_os
3.2.1
appleiphone_os
4.0
appleiphone_os
4.0
appleiphone_os
4.0
appleiphone_os
4.0.1
appleiphone_os
4.0.1
appleiphone_os
4.0.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
freetype
bullseye
2.10.4+dfsg-1+deb11u1
fixed
bookworm
2.12.1+dfsg-5+deb12u3
fixed
sid
2.13.3+dfsg-1
fixed
trixie
2.13.3+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
freetype
lucid
Fixed 2.3.11-1ubuntu2.2
released
karmic
Fixed 2.3.9-5ubuntu0.2
released
jaunty
Fixed 2.3.9-4ubuntu0.3
released
hardy
Fixed 2.3.5-1ubuntu4.8.04.4
released
dapper
Fixed 2.1.10-1ubuntu2.8
released
References