Bug 625626 (CVE-2010-2805)
| Summary: | CVE-2010-2805 freetype: FT_Stream_EnterFrame() does not properly validate certain position values | ||||||
|---|---|---|---|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Vincent Danen <vdanen> | ||||
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||
| Status: | CLOSED ERRATA | QA Contact: | |||||
| Severity: | high | Docs Contact: | |||||
| Priority: | high | ||||||
| Version: | unspecified | CC: | jlieskov, mjc, mkasik, sparks | ||||
| Target Milestone: | --- | Keywords: | Security | ||||
| Target Release: | --- | ||||||
| Hardware: | All | ||||||
| OS: | Linux | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | Doc Type: | Bug Fix | |||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2014-06-02 18:46:58 UTC | Type: | --- | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Bug Depends On: | 638522, 638838, 638839 | ||||||
| Bug Blocks: | |||||||
| Attachments: |
|
||||||
|
Description
Vincent Danen
2010-08-20 00:29:44 UTC
Created attachment 449832 [details]
Public PoC
This issue did NOT affect the versions of the freetype package, as shipped with Red Hat Enterprise Linux 3, 4, or 5. -- This issue affects the versions of the freetype package, as shipped with Fedora release of 12 and 13. This issue did NOT affect the versions of the mingw32-freetype package, as shipped with Fedora release of 12 and 13 and as present within EPEL-5 repository. Statement: Not vulnerable. This issue did not affect the versions of freetype as shipped with Red Hat Enterprise Linux 3, 4, or 5. Created freetype tracking bugs for this issue Affects: fedora-all [bug 638522] This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2010:0864 https://rhn.redhat.com/errata/RHSA-2010-0864.html |