CVE-2010-2498

Source
https://cve.org/CVERecord?id=CVE-2010-2498
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2010-2498.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2010-2498
Downstream
Withdrawn
2026-01-27T04:10:21.281068Z
Published
2010-08-19T18:00:04Z
Modified
2026-01-27T04:10:21.281068Z
Summary
[none]
Details

The pshglyphfindstrongpoints function in pshinter/pshalgo.c in FreeType before 2.4.0 does not properly implement hinting masks, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted font file that triggers an invalid free operation.

References

Affected packages