CVE-2010-2498

Published: August 19th, 2010
The psh_glyph_find_strong_points function in pshinter/pshalgo.c in FreeType before 2.4.0 does not properly implement hinting masks, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted font file that triggers an invalid free operation.
MEDIUM
CVSS v2: 6.8

Status

DocFilters Release Package State Justification Comment
0.0.0.1 freetype (2.13.3) Not Affected Code Not Present 2.13.3 does not match CVE configuration.
26.1.1 freetype (2.13.3) Not Affected Code Not Present 2.13.3 does not match CVE configuration.
26.1 freetype (2.13.3) Not Affected Code Not Present 2.13.3 does not match CVE configuration.
25.4 freetype (2.13.3) Not Affected Code Not Present 2.13.3 does not match CVE configuration.
25.3 freetype (2.13.3) Not Affected Code Not Present 2.13.3 does not match CVE configuration.
25.2 freetype (2.13.3) Not Affected Code Not Present 2.13.3 does not match CVE configuration.
25.1.2 freetype (2.13.3) Not Affected Code Not Present 2.13.3 does not match CVE configuration.
25.1.1 freetype (2.13.3) Not Affected Code Not Present 2.13.3 does not match CVE configuration.
25.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
24.4 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
24.4.0 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
24.3 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
24.2.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
24.2 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
24.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
23.3 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
23.2.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
23.2 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
23.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
22.4 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
22.3 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
22.2 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
22.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
21.11.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
21.11 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
21.8.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
21.8 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.

Severity score breakdown

References