CVE-2010-1797
57Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 31%
from disclosure to weapon0 days
Published on NVDAug 16
1st PoCAug 3
VulnCheckAug 5
exploitation probability
31%top 2% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted CFF opcodes in embedded fonts in a PDF document, as demonstrated by JailbreakMe. NOTE: some of these details are obtained from third party information.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencewww.exploit-db.com/exploits/14538unverifiedexploitdbwww.exploit-db.com/exploits/14538unverifiedexploitdbwww.exploit-db.com/exploits/14727unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://freetype.sourceforge.net/index2.html#release-freetype-2.4.2http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=018f5c27813dd7eef4648fe254632ecea0c85a50http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=11d65e8a1f1f14e56148fd991965424d9bd1cdbchttp://lists.apple.com/archives/security-announce/2010//Aug/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2010//Aug/msg00001.htmlhttp://osvdb.org/66828https://bugs.launchpad.net/ubuntu/maverick/+source/freetype/+bug/617019https://bugzilla.redhat.com/show_bug.cgi?id=621144http://secunia.com/advisories/40807http://secunia.com/advisories/40816http://secunia.com/advisories/40982http://secunia.com/advisories/48951