Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Compact Font Format (CFF) font file that triggers a heap-based buffer overflow, related to an "input stream position error" issue, a different vulnerability than CVE-2010-1797.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2011-01-07 15:00
Updated : 2023-02-12 20:23
NVD link : CVE-2010-3311
Mitre link : CVE-2010-3311
JSON object : View
CWE
CWE-189
Numeric Errors
Products Affected
freetype
- freetype