CVE Vulnerabilities

CVE-2008-1808

Published: Jun 16, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple off-by-one errors in FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via (1) a crafted table in a Printer Font Binary (PFB) file or (2) a crafted SHC instruction in a TrueType Font (TTF) file, which triggers a heap-based buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
FreetypeFreetype1.3.1 (including)1.3.1 (including)
FreetypeFreetype2.0.6 (including)2.0.6 (including)
FreetypeFreetype2.0.9 (including)2.0.9 (including)
FreetypeFreetype2.1.7 (including)2.1.7 (including)
FreetypeFreetype2.1.9 (including)2.1.9 (including)
FreetypeFreetype2.1.10 (including)2.1.10 (including)
FreetypeFreetype2.2.0 (including)2.2.0 (including)
FreetypeFreetype2.2.1 (including)2.2.1 (including)
FreetypeFreetype2.2.10 (including)2.2.10 (including)
FreetypeFreetype2.3.3 (including)2.3.3 (including)
FreetypeFreetype2.3.4 (including)2.3.4 (including)
FreetypeFreetype2.3.5 (including)2.3.5 (including)
Red Hat Enterprise Linux 2.1RedHatfreetype-0:2.0.3-15.el21*
Red Hat Enterprise Linux 3RedHatfreetype-0:2.1.4-10.el3*
Red Hat Enterprise Linux 3RedHatfreetype-0:2.1.4-12.el3*
Red Hat Enterprise Linux 4RedHatfreetype-0:2.1.9-8.el4.6*
Red Hat Enterprise Linux 4RedHatfreetype-0:2.1.9-10.el4.7*
Red Hat Enterprise Linux 5RedHatfreetype-0:2.2.1-20.el5_2*
FreetypeUbuntudapper*
FreetypeUbuntufeisty*
FreetypeUbuntugutsy*
FreetypeUbuntuhardy*
FreetypeUbuntuupstream*

References