The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file.
CVSS Details
- CVSS 3.0 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-freetype | Sep 20, 2017 | Mar 6, 2017 | |
| Debian | debian-upgrade-freetype | Mar 31, 2017 | Mar 6, 2017 | |
| Gentoo Linux | gentoo-linux-upgrade-media-libs-freetype | Oct 30, 2017 | Mar 6, 2017 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Aug 25, 2016 | |
| Suse | — | suse-upgrade-freetype2suse-upgrade-freetype2-32bitsuse-upgrade-freetype2-develsuse-upgrade-freetype2-devel-32bitsuse-upgrade-freetype2-x86suse-upgrade-ft2demossuse-upgrade-libfreetype6suse-upgrade-libfreetype6-32bit | Feb 10, 2018 | Mar 6, 2017 |
| Ubuntu | ubuntu-upgrade-libfreetype6 | Mar 21, 2017 | Mar 6, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub