Unrated severityNVD Advisory· Published Nov 26, 2010· Updated Apr 29, 2026
CVE-2010-3855
CVE-2010-3855
Description
Buffer overflow in the ft_var_readpackedpoints function in truetype/ttgxvar.c in FreeType 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TrueType GX font.
Affected products
32cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*+ 31 more
- cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*range: <=2.4.3
- cpe:2.3:a:freetype:freetype:1.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.1.10:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.1.9:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.2.10:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.3.10:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.3.11:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.3.12:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.3.4:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.3.6:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.3.7:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.3.8:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.3.9:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:freetype:freetype:2.4.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
30- bugs.debian.org/cgi-bin/bugreport.cginvd
- git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/nvd
- lists.apple.com/archives/security-announce/2011//Jul/msg00000.htmlnvd
- lists.apple.com/archives/security-announce/2011//Jul/msg00001.htmlnvd
- lists.apple.com/archives/security-announce/2011//Mar/msg00003.htmlnvd
- lists.apple.com/archives/security-announce/2011//Mar/msg00005.htmlnvd
- lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2010-November/050965.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2010-November/051231.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2010-November/051251.htmlnvd
- secunia.com/advisories/42289nvd
- secunia.com/advisories/42295nvd
- secunia.com/advisories/43138nvd
- secunia.com/advisories/48951nvd
- support.apple.com/kb/HT4564nvd
- support.apple.com/kb/HT4565nvd
- support.apple.com/kb/HT4581nvd
- support.apple.com/kb/HT4802nvd
- support.apple.com/kb/HT4803nvd
- support.avaya.com/css/P8/documents/100122733nvd
- www.debian.org/security/2011/dsa-2155nvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.redhat.com/support/errata/RHSA-2010-0889.htmlnvd
- www.securityfocus.com/bid/44214nvd
- www.securitytracker.com/idnvd
- www.ubuntu.com/usn/USN-1013-1nvd
- www.vupen.com/english/advisories/2010/3037nvd
- www.vupen.com/english/advisories/2011/0246nvd
- savannah.nongnu.org/bugs/nvd
News mentions
0No linked articles in our index yet.