Files
cve/2010/CVE-2010-2520.md
2025-09-29 21:09:30 +02:00

2.5 KiB

CVE-2010-2520

Description

Heap-based buffer overflow in the Ins_IUP function in truetype/ttinterp.c in FreeType before 2.4.0, when TrueType bytecode support is enabled, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.

POC

Reference

No PoCs from references.

Github