Security Advisory

CVE-2007-2754

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2007-05-17 22:00:00
Last updated 2024-08-07 13:49:57
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.