The Load_SBit_Png function in sfnt/pngshim.c in FreeType before 2.5.4 does not restrict the rows and pitch values of PNG data, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact by embedding a PNG file in a .ttf font file.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade freetype | Jul 30, 2024 | Feb 8, 2015 |
| Gentoo Linux | — | Upgrade media-libs/freetype. | Oct 30, 2017 | Feb 8, 2015 |
| Suse | — | Upgrade ftgammaUpgrade freetype2Upgrade freetype2-develUpgrade freetype2-x86Upgrade ftbenchUpgrade freetype2-devel-32bitUpgrade ftvalidUpgrade ftstringUpgrade ftdumpUpgrade ftlintUpgrade ftinspectUpgrade freetype2-32bitUpgrade ftgridUpgrade ftviewUpgrade ftdiffUpgrade libfreetype6-32bitUpgrade libfreetype6Upgrade ft2demosUpgrade ftmulti | Dec 18, 2015 | Feb 8, 2015 |
| Ubuntu | — | Upgrade libfreetype6 | Nov 8, 2024 | Feb 8, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub