CVE-2010-1797

EUVD-2010-1817
Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted CFF opcodes in embedded fonts in a PDF document, as demonstrated by JailbreakMe. NOTE: some of these details are obtained from third party information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Affected Products (NVD)
VendorProductVersion
appleiphone_os
1.0.0
appleiphone_os
1.0.1
appleiphone_os
1.0.1
appleiphone_os
1.0.2
appleiphone_os
1.0.2
appleiphone_os
1.1.0
appleiphone_os
1.1.0
appleiphone_os
1.1.0
appleiphone_os
1.1.1
appleiphone_os
1.1.1
appleiphone_os
1.1.2
appleiphone_os
1.1.2
appleiphone_os
1.1.2
appleiphone_os
1.1.3
appleiphone_os
1.1.3
appleiphone_os
1.1.3
appleiphone_os
1.1.4
appleiphone_os
1.1.4
appleiphone_os
1.1.4
appleiphone_os
1.1.5
appleiphone_os
1.1.5
appleiphone_os
1.1.5
appleiphone_os
2.0
appleiphone_os
2.0.0
appleiphone_os
2.0.0
appleiphone_os
2.0.0
appleiphone_os
2.0.1
appleiphone_os
2.0.1
appleiphone_os
2.0.1
appleiphone_os
2.0.2
appleiphone_os
2.0.2
appleiphone_os
2.0.2
appleiphone_os
2.1
appleiphone_os
2.1
appleiphone_os
2.1
appleiphone_os
2.1.1
appleiphone_os
2.2
appleiphone_os
2.2
appleiphone_os
2.2.1
appleiphone_os
2.2.1
appleiphone_os
2.2.1
appleiphone_os
3.0
appleiphone_os
3.0
appleiphone_os
3.0
appleiphone_os
3.0.1
appleiphone_os
3.0.1
appleiphone_os
3.1
appleiphone_os
3.1
appleiphone_os
3.1
appleiphone_os
3.1.2
appleiphone_os
3.1.2
appleiphone_os
3.1.2
appleiphone_os
3.1.3
appleiphone_os
3.1.3
appleiphone_os
3.2
appleiphone_os
3.2
appleiphone_os
3.2
appleiphone_os
3.2.1
appleiphone_os
3.2.1
appleiphone_os
4.0
appleiphone_os
4.0
appleiphone_os
4.0
appleiphone_os
4.0.1
appleiphone_os
4.0.1
appleiphone_os
4.0.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
freetype
bookworm
2.12.1+dfsg-5+deb12u3
fixed
bullseye
2.10.4+dfsg-1+deb11u1
fixed
sid
2.13.3+dfsg-1
fixed
trixie
2.13.3+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
freetype
dapper
Fixed 2.1.10-1ubuntu2.8
released
hardy
Fixed 2.3.5-1ubuntu4.8.04.4
released
jaunty
Fixed 2.3.9-4ubuntu0.3
released
karmic
Fixed 2.3.9-5ubuntu0.2
released
lucid
Fixed 2.3.11-1ubuntu2.2
released
References