The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly update the current position for immediates-only mode, which allows remote attackers to cause a denial of service (infinite loop) via a Type42 font.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade freetype | Jul 30, 2024 | Jun 7, 2016 |
| F5 Big Ip | — | — | Feb 16, 2017 | Jun 7, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade freetype-develUpgrade freetype | Dec 4, 2019 | Jun 7, 2016 |
| Huawei Euleros 2_0_sp3 | — | Upgrade freetypeUpgrade freetype-devel | Dec 18, 2019 | Jun 7, 2016 |
| Huawei Euleros 2_0_sp5 | — | Upgrade freetypeUpgrade freetype-devel | Nov 19, 2019 | Jun 7, 2016 |
| Oracle Solaris | — | Upgrade system/library/freetype-2 to version 2.5.5-0.175.2.10.0.3.1434 on Solaris 11.2Upgrade consolidation/X/X-incorporation to version 0.5.11-0.175.3.0.0.30.1483 on Solaris 11.3 | May 29, 2017 | Jun 7, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 22, 2014 |
| Suse | — | Upgrade freetype2-32bitUpgrade ft2demosUpgrade freetype2Upgrade freetype2-develUpgrade freetype2-devel-32bitUpgrade freetype2-x86 | Apr 25, 2016 | Apr 25, 2016 |
| Ubuntu | — | Upgrade freetype | Nov 19, 2024 | Jun 7, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub