« List of all CVEs

CVE-2010-3814

Published: 11/26/2010 Last updated: 8/7/2024 Reserved: 10/7/2010

Heap-based buffer overflow in the Ins_SHZ function in ttinterp.c in FreeType 2.4.3 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted SHZ bytecode instruction, related to TrueType opcodes, as demonstrated by a PDF document with a crafted embedded font.

CNA assigner: apple (286789f9-fbc2-4510-9f9a-43facdede74c) Requested by: n/a

Opam packages affected (2)

conf-freetype conf-gd

Products affected (1)

Product Vendor Version
n/a n/a n/a

References (34)