CVE Vulnerabilities

CVE-2011-0226

Published: Jul 19, 2011 | Modified: Oct 26, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Type 1 font in a PDF document, as exploited in the wild in July 2011.

Affected Software

Name Vendor Start Version End Version
Freetype Freetype * 2.4.5 (including)
Freetype Freetype 2.2.1 (including) 2.2.1 (including)
Freetype Freetype 2.2.10 (including) 2.2.10 (including)
Freetype Freetype 2.3.0 (including) 2.3.0 (including)
Freetype Freetype 2.3.1 (including) 2.3.1 (including)
Freetype Freetype 2.3.2 (including) 2.3.2 (including)
Freetype Freetype 2.3.3 (including) 2.3.3 (including)
Freetype Freetype 2.3.4 (including) 2.3.4 (including)
Freetype Freetype 2.3.5 (including) 2.3.5 (including)
Freetype Freetype 2.3.6 (including) 2.3.6 (including)
Freetype Freetype 2.3.7 (including) 2.3.7 (including)
Freetype Freetype 2.3.8 (including) 2.3.8 (including)
Freetype Freetype 2.3.9 (including) 2.3.9 (including)
Freetype Freetype 2.3.10 (including) 2.3.10 (including)
Freetype Freetype 2.3.11 (including) 2.3.11 (including)
Freetype Freetype 2.3.12 (including) 2.3.12 (including)
Freetype Freetype 2.4.0 (including) 2.4.0 (including)
Freetype Freetype 2.4.1 (including) 2.4.1 (including)
Freetype Freetype 2.4.2 (including) 2.4.2 (including)
Freetype Freetype 2.4.3 (including) 2.4.3 (including)
Freetype Freetype 2.4.4 (including) 2.4.4 (including)

References