CVE Vulnerabilities

CVE-2010-3311

Published: Jan 07, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Compact Font Format (CFF) font file that triggers a heap-based buffer overflow, related to an input stream position error issue, a different vulnerability than CVE-2010-1797.

Affected Software

NameVendorStart VersionEnd Version
FreetypeFreetype*2.3.12 (including)
FreetypeFreetype1.3.1 (including)1.3.1 (including)
FreetypeFreetype2.0.6 (including)2.0.6 (including)
FreetypeFreetype2.0.9 (including)2.0.9 (including)
FreetypeFreetype2.1 (including)2.1 (including)
FreetypeFreetype2.1.3 (including)2.1.3 (including)
FreetypeFreetype2.1.4 (including)2.1.4 (including)
FreetypeFreetype2.1.5 (including)2.1.5 (including)
FreetypeFreetype2.1.6 (including)2.1.6 (including)
FreetypeFreetype2.1.7 (including)2.1.7 (including)
FreetypeFreetype2.1.8 (including)2.1.8 (including)
FreetypeFreetype2.1.8-rc1 (including)2.1.8-rc1 (including)
FreetypeFreetype2.1.9 (including)2.1.9 (including)
FreetypeFreetype2.1.10 (including)2.1.10 (including)
FreetypeFreetype2.2.0 (including)2.2.0 (including)
FreetypeFreetype2.2.1 (including)2.2.1 (including)
FreetypeFreetype2.2.10 (including)2.2.10 (including)
FreetypeFreetype2.3.0 (including)2.3.0 (including)
FreetypeFreetype2.3.1 (including)2.3.1 (including)
FreetypeFreetype2.3.2 (including)2.3.2 (including)
FreetypeFreetype2.3.3 (including)2.3.3 (including)
FreetypeFreetype2.3.4 (including)2.3.4 (including)
FreetypeFreetype2.3.5 (including)2.3.5 (including)
FreetypeFreetype2.3.6 (including)2.3.6 (including)
FreetypeFreetype2.3.7 (including)2.3.7 (including)
FreetypeFreetype2.3.8 (including)2.3.8 (including)
FreetypeFreetype2.3.9 (including)2.3.9 (including)
FreetypeFreetype2.3.10 (including)2.3.10 (including)
FreetypeFreetype2.3.11 (including)2.3.11 (including)
Red Hat Enterprise Linux 3RedHatfreetype-0:2.1.4-18.el3*
Red Hat Enterprise Linux 4RedHatfreetype-0:2.1.9-17.el4.8*
Red Hat Enterprise Linux 5RedHatfreetype-0:2.2.1-28.el5_5*
Red Hat Enterprise Linux 6RedHatfreetype-0:2.3.11-6.el6_0.1*
FreetypeUbuntudapper*
FreetypeUbuntuhardy*
FreetypeUbuntujaunty*
FreetypeUbuntukarmic*
FreetypeUbuntulucid*
FreetypeUbuntuupstream*

References