CVE-2007-2754
Published: 17 May 2007
Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.
Priority
Status
Package | Release | Status |
---|---|---|
freetype Launchpad, Ubuntu, Debian |
dapper |
Released
(2.1.10-1ubuntu2.4)
|
edgy |
Released
(2.2.1-5ubuntu0.2)
|
|
feisty |
Released
(2.2.1-5ubuntu1.1)
|
|
upstream |
Needs triage
|
|
openoffice.org-l10n Launchpad, Ubuntu, Debian |
dapper |
Not vulnerable
|
edgy |
Not vulnerable
|
|
feisty |
Not vulnerable
|
|
upstream |
Needs triage
|