The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain position values, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2010-08-19T17:43:00

Updated: 2024-08-07T02:46:48.055Z

Reserved: 2010-07-22T00:00:00

Link: CVE-2010-2805

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-08-19T18:00:04.920

Modified: 2024-11-21T01:17:24.547

Link: CVE-2010-2805

cve-icon Redhat

Severity : Important

Publid Date: 2010-08-04T00:00:00Z

Links: CVE-2010-2805 - Bugzilla