CVE Vulnerabilities

CVE-2010-3054

Published: Aug 19, 2010 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

Unspecified vulnerability in FreeType 2.3.9, and other versions before 2.4.2, allows remote attackers to cause a denial of service via vectors involving nested Standard Encoding Accented Character (aka seac) calls, related to psaux.h, cffgload.c, cffgload.h, and t1decode.c.

Affected Software

Name Vendor Start Version End Version
Freetype Freetype 2.3.9 (including) 2.3.9 (including)
Freetype Freetype 2.3.10 (including) 2.3.10 (including)
Freetype Freetype 2.3.11 (including) 2.3.11 (including)
Freetype Freetype 2.3.12 (including) 2.3.12 (including)
Freetype Freetype 2.4.0 (including) 2.4.0 (including)
Freetype Freetype 2.4.1 (including) 2.4.1 (including)
Red Hat Enterprise Linux 3 RedHat freetype-0:2.1.4-18.el3 *
Red Hat Enterprise Linux 4 RedHat freetype-0:2.1.9-17.el4.8 *
Red Hat Enterprise Linux 5 RedHat freetype-0:2.2.1-28.el5_5 *
Freetype Ubuntu jaunty *
Freetype Ubuntu karmic *
Freetype Ubuntu upstream *

References