CVE-2010-3814
Publication date 22 October 2010
Last updated 24 July 2024
Ubuntu priority
Heap-based buffer overflow in the Ins_SHZ function in ttinterp.c in FreeType 2.4.3 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted SHZ bytecode instruction, related to TrueType opcodes, as demonstrated by a PDF document with a crafted embedded font.
Status
Package | Ubuntu Release | Status |
---|---|---|
freetype | ||
Notes
References
Related Ubuntu Security Notices (USN)
- USN-1013-1
- FreeType vulnerabilities
- 4 November 2010