CVE-2010-3053: Input Validation
Published Aug 19, 2010
·Updated
bdf/bdflib.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) via a crafted BDF font file, related to an attempted modification of a value in a static string.
Affected Software
30 affected components
FreeType<=2.4.1
FreeType=1.3.1
FreeType=2.0.6
FreeType=2.0.9
FreeType=2.1
FreeType=2.1.3
FreeType=2.1.4
FreeType=2.1.5
FreeType=2.1.6
FreeType=2.1.7
FreeType=2.1.8
FreeType=2.1.9
FreeType=2.1.10
FreeType=2.2.0
FreeType=2.2.1
FreeType=2.2.10
FreeType=2.3.0
FreeType=2.3.1
FreeType=2.3.2
FreeType=2.3.3
FreeType=2.3.4
FreeType=2.3.5
FreeType=2.3.6
FreeType=2.3.7
FreeType=2.3.8
FreeType=2.3.9
FreeType=2.3.10
FreeType=2.3.11
FreeType=2.3.12
FreeType=2.4.0
Event History
Aug 19, 2010
CVE Published
via MITRE·05:43 PM
Data Sourced
via MITRE·05:43 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-3053?
CVE-2010-3053 has been classified as a denial of service vulnerability that can lead to application crashes.
2
How do I fix CVE-2010-3053?
To mitigate CVE-2010-3053, users should upgrade FreeType to version 2.4.2 or later.
3
What impact does CVE-2010-3053 have on affected systems?
CVE-2010-3053 allows remote attackers to cause a denial of service through the use of crafted BDF font files.
4
Which versions of FreeType are affected by CVE-2010-3053?
FreeType versions prior to 2.4.2, including 2.4.0, 2.3.x, and 1.3.1, are affected by CVE-2010-3053.
5
Is there a workaround for CVE-2010-3053?
There is no known workaround for CVE-2010-3053; upgrading to a fixed version is the recommended solution.