ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Freetype | Freetype | * | 2.2 (excluding) |
| Red Hat Enterprise Linux 3 | RedHat | freetype-0:2.1.4-4.0.rhel3.2 | * |
| Red Hat Enterprise Linux 4 | RedHat | freetype-0:2.1.9-1.rhel4.4 | * |
| Freetype | Ubuntu | dapper | * |