CVE Vulnerabilities

CVE-2008-1807

Published: Jun 16, 2008 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via an invalid number of axes field in a Printer Font Binary (PFB) file, which triggers a free of arbitrary memory locations, leading to memory corruption.

Affected Software

Name Vendor Start Version End Version
Freetype Freetype 1.3.1 (including) 1.3.1 (including)
Freetype Freetype 2.3.3 (including) 2.3.3 (including)
Freetype Freetype 2.3.4 (including) 2.3.4 (including)
Freetype Freetype 2.3.5 (including) 2.3.5 (including)
Red Hat Enterprise Linux 2.1 RedHat freetype-0:2.0.3-15.el21 *
Red Hat Enterprise Linux 3 RedHat freetype-0:2.1.4-10.el3 *
Red Hat Enterprise Linux 4 RedHat freetype-0:2.1.9-8.el4.6 *
Red Hat Enterprise Linux 5 RedHat freetype-0:2.2.1-20.el5_2 *
Freetype Ubuntu dapper *
Freetype Ubuntu feisty *
Freetype Ubuntu gutsy *
Freetype Ubuntu hardy *
Freetype Ubuntu upstream *

References