REDHAT-BUG-621980: Buffer Overflow

Published Aug 6, 2010
·
Updated

An array index error, leading to heap-based buffer overflow was found in the way the FreeType font rendering engine processed FontType42 font files with negative length of certain special font name table strings. An attacker could use this flaw to create a specially-crafted font file (which bypasses a size check and triggers a heap-based buffer overflow). Such file, when opened, would cause an application linked against libfreetype to crash, or, possibly execute arbitrary code.

Upstream bug report: [1] https://savannah.nongnu.org/bugs/?30656 Public reproducer: [2] http://alt.swiecki.net/j/f/sigsegv29.ttf Upstream changeset: [3] http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=c06da1ad34663da7b6fc39b030dc3ae185b96557

Affected Software

1 affected component
GNU FreeType

Event History

Aug 6, 2010
Data Sourced
04:51 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-621980?

The severity of REDHAT-BUG-621980 is classified as high with a rating of 7.

2

How do I fix REDHAT-BUG-621980?

To fix REDHAT-BUG-621980, ensure you update your GNU FreeType software to a version that has patched this vulnerability.

3

What type of vulnerability is REDHAT-BUG-621980?

REDHAT-BUG-621980 is a buffer overflow vulnerability caused by an array index error in the FreeType font rendering engine.

4

What impact can REDHAT-BUG-621980 have on my system?

An attacker can exploit REDHAT-BUG-621980 by creating a specially-crafted font file that can lead to a heap-based buffer overflow, potentially allowing arbitrary code execution.

5

Which software is affected by REDHAT-BUG-621980?

REDHAT-BUG-621980 affects the GNU FreeType font rendering engine.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203