CVE Database
/

CVE-2007-2754

Back to search

CVE-2007-2754

Published: May 17, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2007-2229
vdb-entry
x_refsource_VUPEN
26129
third-party-advisory
x_refsource_SECUNIA
25612
third-party-advisory
x_refsource_SECUNIA
ADV-2008-0049
vdb-entry
x_refsource_VUPEN
25894
third-party-advisory
x_refsource_SECUNIA
DSA-1334
vendor-advisory
x_refsource_DEBIAN
25386
third-party-advisory
x_refsource_SECUNIA
28298
third-party-advisory
x_refsource_SECUNIA
103171
vendor-advisory
x_refsource_SUNALERT
25705
third-party-advisory
x_refsource_SECUNIA
DSA-1302
vendor-advisory
x_refsource_DEBIAN
36509
vdb-entry
x_refsource_OSVDB
SUSE-SA:2007:041
vendor-advisory
x_refsource_SUSE
FEDORA-2009-5644
vendor-advisory
x_refsource_FEDORA
35074
third-party-advisory
x_refsource_SECUNIA
26305
third-party-advisory
x_refsource_SECUNIA
20070613 FLEA-2007-0025-1: openoffice.org
mailing-list
x_refsource_BUGTRAQ
FEDORA-2009-5558
vendor-advisory
x_refsource_FEDORA
24074
vdb-entry
x_refsource_BID
RHSA-2009:1062
vendor-advisory
x_refsource_REDHAT
APPLE-SA-2009-05-12
vendor-advisory
x_refsource_APPLE
25463
third-party-advisory
x_refsource_SECUNIA
MDKSA-2007:121
vendor-advisory
x_refsource_MANDRIVA
200033
vendor-advisory
x_refsource_SUNALERT
RHSA-2007:0403
vendor-advisory
x_refsource_REDHAT
APPLE-SA-2007-11-14
vendor-advisory
x_refsource_APPLE
25353
third-party-advisory
x_refsource_SECUNIA
30161
third-party-advisory
x_refsource_SECUNIA
GLSA-200805-07
vendor-advisory
x_refsource_GENTOO
GLSA-200707-02
vendor-advisory
x_refsource_GENTOO
2007-0019
vendor-advisory
x_refsource_TRUSTIX
OpenPKG-SA-2007.018
vendor-advisory
x_refsource_OPENPKG
102967
vendor-advisory
x_refsource_SUNALERT
[ft-devel] 20070427 Bug in fuzzed TTF file
mailing-list
x_refsource_MLIST
TA09-133A
third-party-advisory
x_refsource_CERT
25808
third-party-advisory
x_refsource_SECUNIA
GLSA-200705-22
vendor-advisory
x_refsource_GENTOO
oval:org.mitre.oval:def:5532
vdb-entry
signature
x_refsource_OVAL
ADV-2009-1297
vdb-entry
x_refsource_VUPEN
25609
third-party-advisory
x_refsource_SECUNIA
35233
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:11325
vdb-entry
signature
x_refsource_OVAL
35200
third-party-advisory
x_refsource_SECUNIA
25350
third-party-advisory
x_refsource_SECUNIA
USN-466-1
vendor-advisory
x_refsource_UBUNTU
ADV-2007-1894
vdb-entry
x_refsource_VUPEN
RHSA-2009:0329
vendor-advisory
x_refsource_REDHAT
25905
third-party-advisory
x_refsource_SECUNIA
35204
third-party-advisory
x_refsource_SECUNIA
25654
third-party-advisory
x_refsource_SECUNIA
25483
third-party-advisory
x_refsource_SECUNIA
1018088
vdb-entry
x_refsource_SECTRACK
20070524 FLEA-2007-0020-1: freetype
mailing-list
x_refsource_BUGTRAQ

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now