CVE Vulnerabilities

CVE-2010-2807

Incorrect Conversion between Numeric Types

Published: Aug 19, 2010 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
5.8 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.

Weakness

When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.

Affected Software

Name Vendor Start Version End Version
Freetype Freetype * 2.4.2 (excluding)
Freetype Ubuntu dapper *
Freetype Ubuntu hardy *
Freetype Ubuntu jaunty *
Freetype Ubuntu karmic *
Freetype Ubuntu lucid *
Freetype Ubuntu upstream *

Potential Mitigations

References