The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file.
CVSS Details
- CVSS 3.0 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade freetype | Sep 20, 2017 | Mar 6, 2017 |
| Debian | — | Upgrade freetype | Mar 31, 2017 | Mar 6, 2017 |
| Gentoo Linux | — | Upgrade media-libs/freetype. | Oct 30, 2017 | Mar 6, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 25, 2016 |
| Suse | — | Upgrade freetype2-x86Upgrade libfreetype6Upgrade freetype2Upgrade ft2demosUpgrade libfreetype6-32bitUpgrade freetype2-32bitUpgrade freetype2-devel-32bitUpgrade freetype2-devel | Feb 10, 2018 | Mar 6, 2017 |
| Ubuntu | — | Upgrade libfreetype6 | Mar 21, 2017 | Mar 6, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub