CVE-2010-2807: Medium severity FreeType FreeType vulnerability
Published Aug 19, 2010
·Updated
FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
Affected Software
9 affected components
FreeType FreeType<2.4.2
Canonical Ubuntu Linux=9.04
Canonical Ubuntu Linux=9.10
Canonical Ubuntu Linux=8.04
Canonical Ubuntu Linux=10.04
Canonical Ubuntu Linux=6.06
Apple iOS and macOS<10.6.5
Apple iPhone OS<4.2
Apple tvOS<4.1.0
Remediation
Patch Available
Event History
Aug 19, 2010
CVE Published
via MITRE·05:43 PM
Data Sourced
via MITRE·05:43 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-2807?
CVE-2010-2807 has a high severity due to its potential to cause application crashes and execute arbitrary code.
2
How do I fix CVE-2010-2807?
To fix CVE-2010-2807, upgrade FreeType to version 2.4.2 or later.
3
What software is affected by CVE-2010-2807?
CVE-2010-2807 affects FreeType versions prior to 2.4.2 and specific versions of Ubuntu and macOS.
4
Can CVE-2010-2807 be exploited remotely?
Yes, CVE-2010-2807 can be exploited remotely through crafted font files.
5
What types of vulnerabilities are related to CVE-2010-2807?
CVE-2010-2807 is related to improper bounds checking and integer data type errors in software.