CVE-2010-2805
published 2010-08-19CVE-2010-2805: The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain position values, which allows remote attackers…
PriorityP432medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
5.11%
91.4th percentile
The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain position values, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | < 4.2 | 4.2 |
| apple | mac_os_x | < 10.6.5 | 10.6.5 |
| apple | tvos | < 4.1.0 | 4.1.0 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | freetype | < freetype 2.4.2-1 (bookworm) | freetype 2.4.2-1 (bookworm) |
| freetype | freetype | < 2.4.2 | 2.4.2 |
| freetype | freetype | >= 0 < 2.4.2-1 | 2.4.2-1 |
| freetype | freetype | >= 0 < 2.4.2-1 | 2.4.2-1 |
| freetype | freetype | >= 0 < 2.4.2-1 | 2.4.2-1 |
| freetype | freetype | >= 0 < 2.4.2-1 | 2.4.2-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w5qw-jrjj-73c5: The FT_Stream_EnterFrame function in base/ftstream
ghsa_unreviewed·2022-05-13
CVE-2010-2805 [MEDIUM] CWE-20 GHSA-w5qw-jrjj-73c5: The FT_Stream_EnterFrame function in base/ftstream
The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain position values, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
OSV
CVE-2010-2805: The FT_Stream_EnterFrame function in base/ftstream
osv·2010-08-19·CVSS 6.8
CVE-2010-2805 [MEDIUM] CVE-2010-2805: The FT_Stream_EnterFrame function in base/ftstream
The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain position values, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
Ubuntu
FreeType vulnerabilities
vendor_ubuntu·2010-08-17
CVE-2010-1797 FreeType vulnerabilities
Title: FreeType vulnerabilities
It was discovered that FreeType did not correctly handle certain malformed
font files. If a user were tricked into using a specially crafted font
file, a remote attacker could cause FreeType to crash or possibly execute
arbitrary code with user privileges.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Red Hat
freetype: FT_Stream_EnterFrame() does not properly validate certain position values
vendor_redhat·2010-08-04·CVSS 6.8
CVE-2010-2805 [MEDIUM] freetype: FT_Stream_EnterFrame() does not properly validate certain position values
freetype: FT_Stream_EnterFrame() does not properly validate certain position values
The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain position values, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
Statement: Not vulnerable. This issue did not affect the versions of freetype as
shipped with Red Hat Enterprise Linux 3, 4, or 5.
Package: freetype (Red Hat Enterprise Linux 4) - Not affected
Package: freetype (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2010-2805: freetype - The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 do...
vendor_debian·2010·CVSS 6.8
CVE-2010-2805 [MEDIUM] CVE-2010-2805: freetype - The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 do...
The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain position values, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
Scope: local
bookworm: resolved (fixed in 2.4.2-1)
bullseye: resolved (fixed in 2.4.2-1)
forky: resolved (fixed in 2.4.2-1)
sid: resolved (fixed in 2.4.2-1)
trixie: resolved (fixed in 2.4.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-2808 CVE-2010-2806 CVE-2010-2805 CVE-2010-3311 freetype various flaws [fedora-all]
bugzilla·2010-09-29·CVSS 6.8
CVE-2010-2808 [MEDIUM] CVE-2010-2808 CVE-2010-2806 CVE-2010-2805 CVE-2010-3311 freetype various flaws [fedora-all]
CVE-2010-2808 CVE-2010-2806 CVE-2010-2805 CVE-2010-3311 freetype various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=621907
Please note: this issue
Bugzilla
CVE-2010-2805 freetype: FT_Stream_EnterFrame() does not properly validate certain position values
bugzilla·2010-08-20·CVSS 6.8
CVE-2010-2805 [MEDIUM] CVE-2010-2805 freetype: FT_Stream_EnterFrame() does not properly validate certain position values
CVE-2010-2805 freetype: FT_Stream_EnterFrame() does not properly validate certain position values
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-2805 to
the following vulnerability:
Name: CVE-2010-2805
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2805
Assigned: 20100722
Reference: MLIST:[oss-security] 20100806 Re: CVE Request -- FreeType -- Memory corruption flaw by processing certain LWFN fonts + three more
Reference: URL: http://marc.info/?l=oss-security&m=128111955616772&w=2
Reference: CONFIRM: http://freetype.sourceforge.net/index2.html#release-freetype-2.4.2
Reference: CONFIRM: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=45a3c76b547511fa9d97aca34b150a0663257375
Reference: CONFIRM: http://sourceforge.net/projects/freetype/fi
http://freetype.sourceforge.net/index2.html#release-freetype-2.4.2http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=45a3c76b547511fa9d97aca34b150a0663257375http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlhttp://marc.info/?l=oss-security&m=128111955616772&w=2http://secunia.com/advisories/40816http://secunia.com/advisories/40982http://secunia.com/advisories/42314http://secunia.com/advisories/42317http://secunia.com/advisories/48951http://sourceforge.net/projects/freetype/files/freetype2/2.4.2/NEWS/viewhttp://support.apple.com/kb/HT4435http://support.apple.com/kb/HT4456http://support.apple.com/kb/HT4457http://www.redhat.com/support/errata/RHSA-2010-0864.htmlhttp://www.securityfocus.com/bid/42285http://www.ubuntu.com/usn/USN-972-1http://www.vupen.com/english/advisories/2010/2018http://www.vupen.com/english/advisories/2010/2106http://www.vupen.com/english/advisories/2010/3045http://www.vupen.com/english/advisories/2010/3046https://bugs.launchpad.net/ubuntu/maverick/+source/freetype/+bug/617019https://savannah.nongnu.org/bugs/?30644http://freetype.sourceforge.net/index2.html#release-freetype-2.4.2http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=45a3c76b547511fa9d97aca34b150a0663257375http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlhttp://marc.info/?l=oss-security&m=128111955616772&w=2http://secunia.com/advisories/40816http://secunia.com/advisories/40982http://secunia.com/advisories/42314http://secunia.com/advisories/42317http://secunia.com/advisories/48951http://sourceforge.net/projects/freetype/files/freetype2/2.4.2/NEWS/viewhttp://support.apple.com/kb/HT4435http://support.apple.com/kb/HT4456http://support.apple.com/kb/HT4457http://www.redhat.com/support/errata/RHSA-2010-0864.htmlhttp://www.securityfocus.com/bid/42285http://www.ubuntu.com/usn/USN-972-1http://www.vupen.com/english/advisories/2010/2018http://www.vupen.com/english/advisories/2010/2106http://www.vupen.com/english/advisories/2010/3045http://www.vupen.com/english/advisories/2010/3046https://bugs.launchpad.net/ubuntu/maverick/+source/freetype/+bug/617019https://savannah.nongnu.org/bugs/?30644
2010-08-19
Published