The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain position values, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2010-08-19T17:43:00

Updated: 2024-08-07T02:46:48.055Z

Reserved: 2010-07-22T00:00:00

Link: CVE-2010-2805

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2010-08-19T18:00:04.920

Modified: 2021-04-06T12:52:22.123

Link: CVE-2010-2805

cve-icon Redhat

Severity : Important

Publid Date: 2010-08-04T00:00:00Z

Links: CVE-2010-2805 - Bugzilla