In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of cur and limit are sensible before going to Again.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade freetype | Jul 30, 2024 | Jul 30, 2019 |
| Huawei Euleros 2_0_sp3 | — | Upgrade freetype-develUpgrade freetype | Apr 16, 2020 | Jul 30, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade freetypeUpgrade freetype-devel | Nov 19, 2019 | Jul 30, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade freetype-develUpgrade freetype | Feb 26, 2020 | Jul 30, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 30, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub