Multiple off-by-one errors in FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via (1) a crafted table in a Printer Font Binary (PFB) file or (2) a crafted SHC instruction in a TrueType Font (TTF) file, which triggers a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx X11 | — | Apply OS X security update 2009-001 | Dec 16, 2011 | Jun 16, 2008 |
| Centos_linux | — | Upgrade freetype-develUpgrade freetype-utilsUpgrade freetype-demosUpgrade freetype | Dec 1, 2016 | Jun 16, 2008 |
| Debian | — | Upgrade freetype | Jul 30, 2024 | Jun 16, 2008 |
| Freebsd | — | Upgrade freetype2 | Dec 10, 2025 | Jul 3, 2008 |
| Gentoo Linux | — | Upgrade media-libs/freetype.Upgrade app-emulation/vmware-workstation.Upgrade app-emulation/vmware-player.Upgrade app-emulation/vmware-server. | Oct 30, 2017 | Jun 16, 2008 |
| Oracle_linux | — | Upgrade freetypeUpgrade freetype-demosUpgrade freetype-devel | Oct 16, 2024 | Jun 16, 2008 |
| Suse | — | Upgrade freetype2-devel-32bitUpgrade freetype2-devel-64bitUpgrade suse-releaseUpgrade freetype2Upgrade freetype2-32bitUpgrade freetype2-x86Upgrade freetype2-develUpgrade freetype2-64bit | Feb 17, 2015 | Jun 16, 2008 |
| Ubuntu | — | Upgrade libfreetype6 | Nov 8, 2024 | Jun 16, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub