Back

HIGH

freetype: Input stream position error by processing Compact Font Format (CFF) font files

Published Jan 7, 2011

Description

Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Compact Font Format (CFF) font file that triggers a heap-based buffer overflow, related to an "input stream position error" issue, a different vulnerability than CVE-2010-1797.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 7, 2011
Updated Aug 7, 2024
Reserved Sep 13, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Sep 30, 2010