CVE-2007-2754
Last modified
CVE-2007-2754 is a vulnerability of currently unknown severity. Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.. EPSS estimates a 5.83% chance of exploitation in the next 30 days.
Description
Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Freetype | Freetype | <= 2.3.4 |
References
- http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-2754?
How severe is CVE-2007-2754?
How do I fix CVE-2007-2754?
Are you affected by CVE-2007-2754?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
