CVE Vulnerabilities

CVE-2008-1807

Published: Jun 16, 2008 | Modified: Oct 11, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via an invalid number of axes field in a Printer Font Binary (PFB) file, which triggers a free of arbitrary memory locations, leading to memory corruption.

Affected Software

Name Vendor Start Version End Version
Freetype Freetype 1.3.1 (including) 1.3.1 (including)
Freetype Freetype 2.3.3 (including) 2.3.3 (including)
Freetype Freetype 2.3.4 (including) 2.3.4 (including)
Freetype Freetype 2.3.5 (including) 2.3.5 (including)

References