CVE-2010-2806

Published: 08/19/2010 18:00:05
Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via negative size values for certain strings in FontType42 font files, leading to a heap-based buffer overflow.
MEDIUM
CVSS v2: 6.8

Status

DocFilters Release Package State Justification Comment
25.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
24.4 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
24.4.0 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
24.3 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
24.2.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
24.2 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
24.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
23.3 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
23.2.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
23.2 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
23.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
22.4 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
22.3 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
22.2 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
22.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
21.11.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
21.11 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
21.8.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
21.8 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.

Severity score breakdown

References