CVE-2010-2808
published 2010-08-19CVE-2010-2808: Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (memory…
PriorityP336medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.50%
90.4th percentile
Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Adobe Type 1 Mac Font File (aka LWFN) font.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | < 4.2 | 4.2 |
| apple | mac_os_x | < 10.6.5 | 10.6.5 |
| apple | tvos | < 4.1.0 | 4.1.0 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | freetype | < freetype 2.4.2-1 (bookworm) | freetype 2.4.2-1 (bookworm) |
| freetype | freetype | < 2.4.2 | 2.4.2 |
| freetype | freetype | >= 0 < 2.4.2-1 | 2.4.2-1 |
| freetype | freetype | >= 0 < 2.4.2-1 | 2.4.2-1 |
| freetype | freetype | >= 0 < 2.4.2-1 | 2.4.2-1 |
| freetype | freetype | >= 0 < 2.4.2-1 | 2.4.2-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gmf8-rm42-fhx8: Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs
ghsa_unreviewed·2022-05-13
CVE-2010-2808 [MEDIUM] CWE-120 GHSA-gmf8-rm42-fhx8: Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs
Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Adobe Type 1 Mac Font File (aka LWFN) font.
OSV
CVE-2010-2808: Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs
osv·2010-08-19·CVSS 6.8
CVE-2010-2808 [MEDIUM] CVE-2010-2808: Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs
Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Adobe Type 1 Mac Font File (aka LWFN) font.
Ubuntu
FreeType vulnerabilities
vendor_ubuntu·2010-08-17
CVE-2010-1797 FreeType vulnerabilities
Title: FreeType vulnerabilities
It was discovered that FreeType did not correctly handle certain malformed
font files. If a user were tricked into using a specially crafted font
file, a remote attacker could cause FreeType to crash or possibly execute
arbitrary code with user privileges.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Red Hat
FreeType: Stack-based buffer overflow by processing certain LWFN fonts
vendor_redhat·2010-08-05·CVSS 6.8
CVE-2010-2808 [MEDIUM] CWE-121 FreeType: Stack-based buffer overflow by processing certain LWFN fonts
FreeType: Stack-based buffer overflow by processing certain LWFN fonts
Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Adobe Type 1 Mac Font File (aka LWFN) font.
Debian
CVE-2010-2808: freetype - Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeT...
vendor_debian·2010·CVSS 6.8
CVE-2010-2808 [MEDIUM] CVE-2010-2808: freetype - Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeT...
Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Adobe Type 1 Mac Font File (aka LWFN) font.
Scope: local
bookworm: resolved (fixed in 2.4.2-1)
bullseye: resolved (fixed in 2.4.2-1)
forky: resolved (fixed in 2.4.2-1)
sid: resolved (fixed in 2.4.2-1)
trixie: resolved (fixed in 2.4.2-1)
No detection rules found.
Bugzilla
CVE-2014-9673 freetype: integer signedness error in Mac_Read_POST_Resource() leading to heap-based buffer overflow
bugzilla·2015-02-10·CVSS 6.8
CVE-2014-9673 [MEDIUM] CVE-2014-9673 freetype: integer signedness error in Mac_Read_POST_Resource() leading to heap-based buffer overflow
CVE-2014-9673 freetype: integer signedness error in Mac_Read_POST_Resource() leading to heap-based buffer overflow
Common Vulnerabilities and Exposures assigned CVE-2014-9673 to the following issue:
Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c
in FreeType before 2.5.4 allows remote attackers to cause a denial of service
(heap-based buffer overflow) or possibly have unspecified other impact via a
crafted Mac font.
http://code.google.com/p/google-security-research/issues/detail?id=154
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=35252ae9aa1dd9343e9f4884e9ddb1fee10ef415
Discussion:
(Private) upstream bug:
https://savannah.nongnu.org/bugs/?43539
Issue was fixed upstream in 2.5.4.
This issue was reported as being a flaw in the bou
Bugzilla
CVE-2014-9674 freetype: multiple integer overflows Mac_Read_POST_Resource() leading to heap-based buffer overflows
bugzilla·2015-02-10·CVSS 6.8
CVE-2014-9674 [MEDIUM] CVE-2014-9674 freetype: multiple integer overflows Mac_Read_POST_Resource() leading to heap-based buffer overflows
CVE-2014-9674 freetype: multiple integer overflows Mac_Read_POST_Resource() leading to heap-based buffer overflows
The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values without validating the original values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact via a crafted Mac font.
Upstream issue:
http://code.google.com/p/google-security-research/issues/detail?id=153
Upstream patches:
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=240c94a185cd8dae7d03059abec8a5662c35ecd3
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=cd4a5a26e591d01494567df9dec7f72d59551f6e
Discussion:
Created freety
Bugzilla
CVE-2010-2808 CVE-2010-2806 CVE-2010-2805 CVE-2010-3311 freetype various flaws [fedora-all]
bugzilla·2010-09-29·CVSS 6.8
CVE-2010-2808 [MEDIUM] CVE-2010-2808 CVE-2010-2806 CVE-2010-2805 CVE-2010-3311 freetype various flaws [fedora-all]
CVE-2010-2808 CVE-2010-2806 CVE-2010-2805 CVE-2010-3311 freetype various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=621907
Please note: this issue
Bugzilla
CVE-2010-2808 FreeType: Stack-based buffer overflow by processing certain LWFN fonts
bugzilla·2010-08-06·CVSS 6.8
CVE-2010-2808 [MEDIUM] CVE-2010-2808 FreeType: Stack-based buffer overflow by processing certain LWFN fonts
CVE-2010-2808 FreeType: Stack-based buffer overflow by processing certain LWFN fonts
A stack-based buffer overflow was found in the way FreeType font
rendering engine processed certain Adobe Type 1 Mac Font File (LWFN)
fonts. An attacker could use this flaw to create a specially-crafted
font file that, when opened, would cause an application linked against
libfreetype to crash, or, possibly execute arbitrary code.
Upstream bug report:
[1] https://savannah.nongnu.org/bugs/?30658
Public reproducer:
[2] http://alt.swiecki.net/j/f/sigsegv31.ttf
Upstream changeset:
[3] http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=81f3472c0ba7b8f6466e2e214fa8c1c17fade975
Credit: Robert Swiecki
Discussion:
This issue does NOT affect the version of the freetype package, as shipped
with
http://freetype.sourceforge.net/index2.html#release-freetype-2.4.2http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=81f3472c0ba7b8f6466e2e214fa8c1c17fade975http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlhttp://marc.info/?l=oss-security&m=128110167119337&w=2http://marc.info/?l=oss-security&m=128111955616772&w=2http://secunia.com/advisories/40816http://secunia.com/advisories/40982http://secunia.com/advisories/42314http://secunia.com/advisories/42317http://sourceforge.net/projects/freetype/files/freetype2/2.4.2/NEWS/viewhttp://support.apple.com/kb/HT4435http://support.apple.com/kb/HT4456http://support.apple.com/kb/HT4457http://www.redhat.com/support/errata/RHSA-2010-0864.htmlhttp://www.securityfocus.com/bid/42285http://www.ubuntu.com/usn/USN-972-1http://www.vupen.com/english/advisories/2010/2018http://www.vupen.com/english/advisories/2010/2106http://www.vupen.com/english/advisories/2010/3045http://www.vupen.com/english/advisories/2010/3046https://bugs.launchpad.net/ubuntu/maverick/+source/freetype/+bug/617019https://bugzilla.redhat.com/show_bug.cgi?id=621907https://rhn.redhat.com/errata/RHSA-2010-0737.htmlhttps://savannah.nongnu.org/bugs/?30658http://freetype.sourceforge.net/index2.html#release-freetype-2.4.2http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=81f3472c0ba7b8f6466e2e214fa8c1c17fade975http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlhttp://marc.info/?l=oss-security&m=128110167119337&w=2http://marc.info/?l=oss-security&m=128111955616772&w=2http://secunia.com/advisories/40816http://secunia.com/advisories/40982http://secunia.com/advisories/42314http://secunia.com/advisories/42317http://sourceforge.net/projects/freetype/files/freetype2/2.4.2/NEWS/viewhttp://support.apple.com/kb/HT4435http://support.apple.com/kb/HT4456http://support.apple.com/kb/HT4457http://www.redhat.com/support/errata/RHSA-2010-0864.htmlhttp://www.securityfocus.com/bid/42285http://www.ubuntu.com/usn/USN-972-1http://www.vupen.com/english/advisories/2010/2018http://www.vupen.com/english/advisories/2010/2106http://www.vupen.com/english/advisories/2010/3045http://www.vupen.com/english/advisories/2010/3046https://bugs.launchpad.net/ubuntu/maverick/+source/freetype/+bug/617019https://bugzilla.redhat.com/show_bug.cgi?id=621907https://rhn.redhat.com/errata/RHSA-2010-0737.htmlhttps://savannah.nongnu.org/bugs/?30658
2010-08-19
Published