CVE-2007-2754: Buffer Overflow
Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative npoints value, which leads to an integer overflow and heap-based buffer overflow.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2754?
CVE-2007-2754 has a severity rating that allows remote attackers to execute arbitrary code, indicating it poses a high risk.
How do I fix CVE-2007-2754?
To fix CVE-2007-2754, update to FreeType version 2.3.5 or later where the vulnerability is patched.
Which versions of FreeType are affected by CVE-2007-2754?
FreeType versions up to and including 2.3.4 are affected by CVE-2007-2754.
What type of attack is possible with CVE-2007-2754?
CVE-2007-2754 allows remote attackers to craft a TTF image that can trigger an integer overflow and subsequently a heap-based buffer overflow.
Is CVE-2007-2754 a known vulnerability?
Yes, CVE-2007-2754 is a known vulnerability that has been documented since its discovery.