CVE-2010-4259 – FontForge - '.BDF' Font File Stack Buffer Overflow (PoC)
https://notcve.org/view.php?id=CVE-2010-4259
Stack-based buffer overflow in FontForge 20100501 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long CHARSET_REGISTRY header in a BDF font file. Desbordamiento de buffer basado en pila en FontForge 20100501 permite a atacantes remotos provocar una denegación de servicio (caída de la aplicación) o posiblemente ejecutar código de su elección mediante una cabecera CHARSET_REGISTRY larga en un fichero de fuentes BDF. • https://www.exploit-db.com/exploits/15732 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=605537 http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052201.html http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052219.html http://openwall.com/lists/oss-security/2010/12/02/5 http://openwall.com/lists/oss-security/2010/12/02/8 http://secunia.com/advisories/42577 http://www.debian.org/security/2011/dsa-2253 http://www.exploit-db.com& • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •