TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2007-2754

N/A

Beschreibung

Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.

CVE Details

CVSS v3.1 BewertungN/A
Veroffentlicht5/17/2007
Zuletzt geandert4/23/2026
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

freetype:freetype

Referenzen

http://osvdb.org/36509(secalert@redhat.com)
http://osvdb.org/36509(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/25350(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/25353(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/25386(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/25463(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/25483(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/25609(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/25612(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/25654(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/25705(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/25808(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/25894(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/25905(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/26129(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/26305(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/28298(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/30161(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/35074(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/35200(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/35204(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/35233(af854a3a-2127-422b-91ae-364da2661108)
http://support.apple.com/kb/HT3549(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2007/dsa-1302(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2007/dsa-1334(af854a3a-2127-422b-91ae-364da2661108)
http://www.gentoo.org/security/en/glsa/glsa-200705-22.xml(af854a3a-2127-422b-91ae-364da2661108)
http://www.gentoo.org/security/en/glsa/glsa-200707-02.xml(af854a3a-2127-422b-91ae-364da2661108)
http://www.gentoo.org/security/en/glsa/glsa-200805-07.xml(af854a3a-2127-422b-91ae-364da2661108)
http://www.redhat.com/support/errata/RHSA-2007-0403.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.redhat.com/support/errata/RHSA-2009-0329.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.redhat.com/support/errata/RHSA-2009-1062.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/24074(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id?1018088(af854a3a-2127-422b-91ae-364da2661108)
http://www.trustix.org/errata/2007/0019/(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/usn-466-1(af854a3a-2127-422b-91ae-364da2661108)
http://www.us-cert.gov/cas/techalerts/TA09-133A.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2007/1894(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2007/2229(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2008/0049(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2009/1297(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=502565(af854a3a-2127-422b-91ae-364da2661108)
https://issues.rpath.com/browse/RPL-1390(af854a3a-2127-422b-91ae-364da2661108)

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.