CVE-2010-2805: Input Validation
The FTStreamEnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain position values, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2805?
CVE-2010-2805 is classified as a high severity vulnerability due to the potential for denial of service and arbitrary code execution.
How do I fix CVE-2010-2805?
To fix CVE-2010-2805, update FreeType to version 2.4.2 or later.
Which software versions are affected by CVE-2010-2805?
CVE-2010-2805 affects FreeType versions prior to 2.4.2 and specific versions of Ubuntu and Apple operating systems.
What type of vulnerability is CVE-2010-2805?
CVE-2010-2805 is a vulnerability that arises due to improper validation of position values in font files.
Can CVE-2010-2805 lead to remote attacks?
Yes, CVE-2010-2805 may allow remote attackers to crash the application or execute malicious code via crafted font files.