CVE-2010-3054: Medium severity FreeType vulnerability
Published Aug 19, 2010
·Updated
Unspecified vulnerability in FreeType 2.3.9, and other versions before 2.4.2, allows remote attackers to cause a denial of service via vectors involving nested Standard Encoding Accented Character (aka seac) calls, related to psaux.h, cffgload.c, cffgload.h, and t1decode.c.
Affected Software
6 affected components
FreeType=2.4.0
FreeType=2.3.10
FreeType=2.4.1
FreeType=2.3.11
FreeType=2.3.12
FreeType=2.3.9
Event History
Aug 19, 2010
CVE Published
via MITRE·05:43 PM
Data Sourced
via MITRE·05:43 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-3054?
CVE-2010-3054 is classified as a denial of service vulnerability.
2
How do I fix CVE-2010-3054?
To fix CVE-2010-3054, you should upgrade FreeType to version 2.4.2 or later.
3
Which versions of FreeType are affected by CVE-2010-3054?
CVE-2010-3054 affects FreeType versions 2.3.9 through 2.4.1.
4
Can CVE-2010-3054 be exploited remotely?
Yes, CVE-2010-3054 can be exploited by remote attackers.
5
What components of FreeType does CVE-2010-3054 involve?
CVE-2010-3054 involves components related to psaux.h, cffgload.c, cffgload.h, and t1decode.c.