CVE-2010-2806
published 2010-08-19CVE-2010-2806: Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service…
PriorityP335medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
5.84%
92.4th percentile
Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via negative size values for certain strings in FontType42 font files, leading to a heap-based buffer overflow.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | < 4.2 | 4.2 |
| apple | mac_os_x | < 10.6.5 | 10.6.5 |
| apple | tvos | < 4.1.0 | 4.1.0 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | freetype | < freetype 2.4.2-1 (bookworm) | freetype 2.4.2-1 (bookworm) |
| freetype | freetype | < 2.4.2 | 2.4.2 |
| freetype | freetype | >= 0 < 2.4.2-1 | 2.4.2-1 |
| freetype | freetype | >= 0 < 2.4.2-1 | 2.4.2-1 |
| freetype | freetype | >= 0 < 2.4.2-1 | 2.4.2-1 |
| freetype | freetype | >= 0 < 2.4.2-1 | 2.4.2-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-69qg-rxrw-rwrh: Array index error in the t42_parse_sfnts function in type42/t42parse
ghsa_unreviewed·2022-05-13
CVE-2010-2806 [MEDIUM] CWE-129 GHSA-69qg-rxrw-rwrh: Array index error in the t42_parse_sfnts function in type42/t42parse
Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via negative size values for certain strings in FontType42 font files, leading to a heap-based buffer overflow.
OSV
CVE-2010-2806: Array index error in the t42_parse_sfnts function in type42/t42parse
osv·2010-08-19·CVSS 6.8
CVE-2010-2806 [MEDIUM] CVE-2010-2806: Array index error in the t42_parse_sfnts function in type42/t42parse
Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via negative size values for certain strings in FontType42 font files, leading to a heap-based buffer overflow.
Ubuntu
FreeType vulnerabilities
vendor_ubuntu·2010-08-17
CVE-2010-1797 FreeType vulnerabilities
Title: FreeType vulnerabilities
It was discovered that FreeType did not correctly handle certain malformed
font files. If a user were tricked into using a specially crafted font
file, a remote attacker could cause FreeType to crash or possibly execute
arbitrary code with user privileges.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Red Hat
FreeType: Heap-based buffer overflow by processing FontType42 fonts with negative length of SFNT strings (FT bug #30656)
vendor_redhat·2010-08-05·CVSS 6.8
CVE-2010-2806 [MEDIUM] CWE-122 FreeType: Heap-based buffer overflow by processing FontType42 fonts with negative length of SFNT strings (FT bug #30656)
FreeType: Heap-based buffer overflow by processing FontType42 fonts with negative length of SFNT strings (FT bug #30656)
Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via negative size values for certain strings in FontType42 font files, leading to a heap-based buffer overflow.
Debian
CVE-2010-2806: freetype - Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeTy...
vendor_debian·2010·CVSS 6.8
CVE-2010-2806 [MEDIUM] CVE-2010-2806: freetype - Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeTy...
Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via negative size values for certain strings in FontType42 font files, leading to a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.4.2-1)
bullseye: resolved (fixed in 2.4.2-1)
forky: resolved (fixed in 2.4.2-1)
sid: resolved (fixed in 2.4.2-1)
trixie: resolved (fixed in 2.4.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-2808 CVE-2010-2806 CVE-2010-2805 CVE-2010-3311 freetype various flaws [fedora-all]
bugzilla·2010-09-29·CVSS 6.8
CVE-2010-2808 [MEDIUM] CVE-2010-2808 CVE-2010-2806 CVE-2010-2805 CVE-2010-3311 freetype various flaws [fedora-all]
CVE-2010-2808 CVE-2010-2806 CVE-2010-2805 CVE-2010-3311 freetype various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=621907
Please note: this issue
Bugzilla
CVE-2010-2806 FreeType: Heap-based buffer overflow by processing FontType42 fonts with negative length of SFNT strings (FT bug #30656)
bugzilla·2010-08-06·CVSS 6.8
CVE-2010-2806 [MEDIUM] CVE-2010-2806 FreeType: Heap-based buffer overflow by processing FontType42 fonts with negative length of SFNT strings (FT bug #30656)
CVE-2010-2806 FreeType: Heap-based buffer overflow by processing FontType42 fonts with negative length of SFNT strings (FT bug #30656)
An array index error, leading to heap-based buffer overflow was found
in the way the FreeType font rendering engine processed FontType42 font
files with negative length of certain special font name table strings.
An attacker could use this flaw to create a specially-crafted font file
(which bypasses a size check and triggers a heap-based buffer overflow).
Such file, when opened, would cause an application linked against libfreetype to crash, or, possibly execute arbitrary code.
Upstream bug report:
[1] https://savannah.nongnu.org/bugs/?30656
Public reproducer:
[2] http://alt.swiecki.net/j/f/sigsegv29.ttf
Upstream changeset:
[3] http://git.savannah.gnu.o
Bugzilla
CVE-2010-1797 CVE-2010-2806 freetype various flaws [fedora-all]
bugzilla·2010-08-05·CVSS 9.3
CVE-2010-1797 [CRITICAL] CVE-2010-1797 CVE-2010-2806 freetype various flaws [fedora-all]
CVE-2010-1797 CVE-2010-2806 freetype various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=621144
Please note: this issue affects multiple supported
http://freetype.sourceforge.net/index2.html#release-freetype-2.4.2http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=c06da1ad34663da7b6fc39b030dc3ae185b96557http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlhttp://marc.info/?l=oss-security&m=128111955616772&w=2http://secunia.com/advisories/40816http://secunia.com/advisories/40982http://secunia.com/advisories/42314http://secunia.com/advisories/42317http://sourceforge.net/projects/freetype/files/freetype2/2.4.2/NEWS/viewhttp://support.apple.com/kb/HT4435http://support.apple.com/kb/HT4456http://support.apple.com/kb/HT4457http://www.redhat.com/support/errata/RHSA-2010-0864.htmlhttp://www.securityfocus.com/bid/42285http://www.ubuntu.com/usn/USN-972-1http://www.vupen.com/english/advisories/2010/2018http://www.vupen.com/english/advisories/2010/2106http://www.vupen.com/english/advisories/2010/3045http://www.vupen.com/english/advisories/2010/3046https://bugs.launchpad.net/ubuntu/maverick/+source/freetype/+bug/617019https://bugzilla.redhat.com/show_bug.cgi?id=621980https://rhn.redhat.com/errata/RHSA-2010-0736.htmlhttps://rhn.redhat.com/errata/RHSA-2010-0737.htmlhttps://savannah.nongnu.org/bugs/?30656http://freetype.sourceforge.net/index2.html#release-freetype-2.4.2http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=c06da1ad34663da7b6fc39b030dc3ae185b96557http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlhttp://marc.info/?l=oss-security&m=128111955616772&w=2http://secunia.com/advisories/40816http://secunia.com/advisories/40982http://secunia.com/advisories/42314http://secunia.com/advisories/42317http://sourceforge.net/projects/freetype/files/freetype2/2.4.2/NEWS/viewhttp://support.apple.com/kb/HT4435http://support.apple.com/kb/HT4456http://support.apple.com/kb/HT4457http://www.redhat.com/support/errata/RHSA-2010-0864.htmlhttp://www.securityfocus.com/bid/42285http://www.ubuntu.com/usn/USN-972-1http://www.vupen.com/english/advisories/2010/2018http://www.vupen.com/english/advisories/2010/2106http://www.vupen.com/english/advisories/2010/3045http://www.vupen.com/english/advisories/2010/3046https://bugs.launchpad.net/ubuntu/maverick/+source/freetype/+bug/617019https://bugzilla.redhat.com/show_bug.cgi?id=621980https://rhn.redhat.com/errata/RHSA-2010-0736.htmlhttps://rhn.redhat.com/errata/RHSA-2010-0737.htmlhttps://savannah.nongnu.org/bugs/?30656
2010-08-19
Published