CVE-2010-4259

Stack-based buffer overflow in FontForge 20100501 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long CHARSET_REGISTRY header in a BDF font file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
Debian logo
Debian Releases
Debian Product
Codename
fontforge
bullseye (security)
1:20201107~dfsg-4+deb11u1
fixed
bullseye
1:20201107~dfsg-4+deb11u1
fixed
bookworm
1:20230101~dfsg-1.1~deb12u1
fixed
bookworm (security)
1:20230101~dfsg-1.1~deb12u1
fixed
sid
1:20230101~dfsg-4
fixed
trixie
1:20230101~dfsg-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
fontforge
raring
Fixed 0.0.20100501-4ubuntu1
released
quantal
Fixed 0.0.20100501-4ubuntu1
released
precise
Fixed 0.0.20100501-4ubuntu1
released
oneiric
Fixed 0.0.20100501-4ubuntu1
released
natty
Fixed 0.0.20100501-4ubuntu1
released
maverick
ignored
lucid
ignored
karmic
ignored
hardy
ignored
dapper
ignored