CVE-2010-2805
19.08.2010, 18:00
The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain position values, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.Enginsight
Vendor | Product | Version |
---|---|---|
freetype | freetype | 𝑥 < 2.4.2 |
canonical | ubuntu_linux | 6.06 |
canonical | ubuntu_linux | 8.04 |
canonical | ubuntu_linux | 9.04 |
canonical | ubuntu_linux | 9.10 |
canonical | ubuntu_linux | 10.04 |
apple | iphone_os | 𝑥 < 4.2 |
apple | mac_os_x | 𝑥 < 10.6.5 |
apple | tvos | 𝑥 < 4.1.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References