CVE-2010-1028
EPSS 8.8%
描述
Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.
如何修補 CVE-2010-1028
要修補 CVE-2010-1028,請將受影響套件升級到下列已修補版本。
- Debian/calibre—升級至 2.38.0+dfsg-1 或更新版本
CVE-2010-1028 正在被利用嗎?
中等 — EPSS 為 8.8%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 2.38.0+dfsg-1