CVE Vulnerabilities

CVE-2007-2754

Published: May 17, 2007 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Freetype Freetype * 2.3.4 (including)
Freetype Ubuntu dapper *
Freetype Ubuntu devel *
Freetype Ubuntu edgy *
Freetype Ubuntu feisty *
Openoffice.org-l10n Ubuntu devel *
Red Hat Enterprise Linux 2.1 RedHat freetype-0:2.0.3-10.el21 *
Red Hat Enterprise Linux 2.1 RedHat freetype-0:2.0.3-17.el21 *
Red Hat Enterprise Linux 3 RedHat freetype-0:2.1.4-7.el3 *
Red Hat Enterprise Linux 3 RedHat freetype-0:2.1.4-12.el3 *
Red Hat Enterprise Linux 4 RedHat freetype-0:2.1.9-6.el4 *
Red Hat Enterprise Linux 4 RedHat freetype-0:2.1.9-10.el4.7 *
Red Hat Enterprise Linux 5 RedHat freetype-0:2.2.1-19.el5 *

References