Lucene search

K
cve[email protected]CVE-2010-2499
HistoryAug 19, 2010 - 6:00 p.m.

CVE-2010-2499

2010-08-1918:00:04
CWE-120
web.nvd.nist.gov
45
3
cve-2010-2499
buffer overflow
mac_read_post_resource
freetype
remote attack
denial of service
arbitrary code execution
laserwriter ps font
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

9 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.7%

Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted LaserWriter PS font file with an embedded PFB fragment.

Affected configurations

NVD
Node
freetypefreetypeRange<2.4.0
Node
canonicalubuntu_linuxMatch6.06
OR
canonicalubuntu_linuxMatch8.04-
OR
canonicalubuntu_linuxMatch9.04
OR
canonicalubuntu_linuxMatch9.10
OR
canonicalubuntu_linuxMatch10.04-
Node
applemac_os_xRange<10.6.5
Node
debiandebian_linuxMatch5.0
CPENameOperatorVersion
freetype:freetypefreetypelt2.4.0

Social References

More

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

9 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.7%