Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Adobe Type 1 Mac Font File (aka LWFN) font.
References
Link Providers
https://www.spirityenterprise.com/pentest spirity
https://www.spirityenterprise.com/managed-detection-response spirity
http://freetype.sourceforge.net/index2.html#release-freetype-2.4.2 cve-icon cve-icon
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=81f3472c0ba7b8f6466e2e214fa8c1c17fade975 cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html cve-icon cve-icon
http://marc.info/?l=oss-security&m=128110167119337&w=2 cve-icon cve-icon
http://marc.info/?l=oss-security&m=128111955616772&w=2 cve-icon cve-icon
http://secunia.com/advisories/40816 cve-icon cve-icon
http://secunia.com/advisories/40982 cve-icon cve-icon
http://secunia.com/advisories/42314 cve-icon cve-icon
http://secunia.com/advisories/42317 cve-icon cve-icon
http://sourceforge.net/projects/freetype/files/freetype2/2.4.2/NEWS/view cve-icon cve-icon
http://support.apple.com/kb/HT4435 cve-icon cve-icon
http://support.apple.com/kb/HT4456 cve-icon cve-icon
http://support.apple.com/kb/HT4457 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2010-0864.html cve-icon cve-icon
http://www.securityfocus.com/bid/42285 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-972-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/2018 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/2106 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/3045 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/3046 cve-icon cve-icon
https://bugs.launchpad.net/ubuntu/maverick/+source/freetype/+bug/617019 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=621907 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2010-2808 cve-icon
https://rhn.redhat.com/errata/RHSA-2010-0737.html cve-icon cve-icon
https://savannah.nongnu.org/bugs/?30658 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2010-2808 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T02:46:48.199Z

Reserved: 2010-07-22T00:00:00

Link: CVE-2010-2808

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2010-08-19T18:00:05.327

Modified: 2025-04-11T00:51:21.963

Link: CVE-2010-2808

cve-icon Redhat

Severity : Important

Publid Date: 2010-08-05T00:00:00Z

Links: CVE-2010-2808 - Bugzilla