CVE-2010-3855: Buffer Overflow
Buffer overflow in the ftvarreadpackedpoints function in truetype/ttgxvar.c in FreeType 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TrueType GX font.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3855?
CVE-2010-3855 has a high severity due to the potential for remote attackers to crash the application or execute arbitrary code.
How do I fix CVE-2010-3855?
To fix CVE-2010-3855, you should upgrade to FreeType version 2.4.4 or later, which contains the required patches.
What types of attacks can CVE-2010-3855 facilitate?
CVE-2010-3855 can facilitate denial of service attacks by crashing applications using vulnerable FreeType versions when processing malicious TrueType fonts.
Which versions of FreeType are affected by CVE-2010-3855?
CVE-2010-3855 affects FreeType versions 2.4.3 and earlier, as well as other specific older versions such as 1.3.1, 2.0.6, and others.
Is it possible to exploit CVE-2010-3855 remotely?
Yes, CVE-2010-3855 can be exploited remotely through crafted TrueType GX fonts, leading to potential application crashes or code execution.