First published: Fri Jul 09 2010(Updated: )
Integer underflow in glyph handling in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
FreeType | <2.4.0 | |
Apple iOS and macOS | <10.6.5 | |
Debian | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2497 has a severity level that can lead to a denial of service or potential arbitrary code execution.
To fix CVE-2010-2497, update FreeType to version 2.4.0 or later.
The potential impacts of CVE-2010-2497 include application crashes and possible remote code execution.
CVE-2010-2497 affects FreeType versions before 2.4.0, macOS versions prior to 10.6.5, and Debian GNU/Linux 5.0.
CVE-2010-2497 was reported by Robert Swiecki.