CVE Vulnerabilities

CVE-2008-1808

Published: Jun 16, 2008 | Modified: Jan 26, 2021
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple off-by-one errors in FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via (1) a crafted table in a Printer Font Binary (PFB) file or (2) a crafted SHC instruction in a TrueType Font (TTF) file, which triggers a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Freetype Freetype 2.1.9 2.1.9
Freetype Freetype 2.1.10 2.1.10
Freetype Freetype 2.3.4 2.3.4
Freetype Freetype 2.3.5 2.3.5
Freetype Freetype 1.3.1 1.3.1
Freetype Freetype 2.2.10 2.2.10
Freetype Freetype 2.2.1 2.2.1
Freetype Freetype 2.3.3 2.3.3
Freetype Freetype 2.0.9 2.0.9
Freetype Freetype 2.0.6 2.0.6
Freetype Freetype 2.1.7 2.1.7
Freetype Freetype 2.2.0 2.2.0

References