Back

MEDIUM

FreeType: Heap-based buffer overflow by processing FontType42 fonts with negative length of SFNT strings (FT bug #30656)

Published Aug 19, 2010

Description

Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via negative size values for certain strings in FontType42 font files, leading to a heap-based buffer overflow.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (28)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 19, 2010
Updated Aug 7, 2024
Reserved Jul 22, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Aug 5, 2010