[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-3855Date: (C)2010-11-26   (M)2024-02-22


Buffer overflow in the ft_var_readpackedpoints function in truetype/ttgxvar.c in FreeType 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TrueType GX font.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.8
Exploit Score: 8.6
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1024745
SECUNIA-42289
SECUNIA-42295
SECUNIA-43138
BID-44214
SECUNIA-48951
ADV-2010-3037
ADV-2011-0246
APPLE-SA-2011-03-09-1
APPLE-SA-2011-03-09-3
APPLE-SA-2011-03-21-1
APPLE-SA-2011-07-15-1
APPLE-SA-2011-07-15-2
DSA-2155
FEDORA-2010-17728
FEDORA-2010-17742
FEDORA-2010-17755
MDVSA-2010:235
MDVSA-2010:236
RHSA-2010:0889
USN-1013-1
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=602221
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=59eb9f8cfe7d1df379a2318316d1f04f80fba54a
http://support.apple.com/kb/HT4564
http://support.apple.com/kb/HT4565
http://support.apple.com/kb/HT4581
http://support.apple.com/kb/HT4802
http://support.apple.com/kb/HT4803
http://support.avaya.com/css/P8/documents/100122733
https://savannah.nongnu.org/bugs/?31310

CWE    1
CWE-119
OVAL    15
oval:org.secpod.oval:def:600200
oval:org.secpod.oval:def:201782
oval:org.secpod.oval:def:102805
oval:org.secpod.oval:def:201697
...

© SecPod Technologies