PT-2008-1133 · Freetype+1 · Freetype2+1

Publicado

2008-06-16

·

Atualizado

2021-01-26

·

CVE-2008-1808

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FreeType2 versions prior to 2.3.6
Description The issue involves multiple off-by-one errors that can be exploited by context-dependent attackers to execute arbitrary code. This can be achieved through a crafted table in a Printer Font Binary (PFB) file or a crafted SHC instruction in a TrueType Font (TTF) file, leading to a heap-based buffer overflow. The exploitation of these vulnerabilities may compromise the confidentiality, integrity, and availability of protected information and can be performed remotely.
Recommendations For FreeType2 versions prior to 2.3.6, update to version 2.3.6 or later to resolve the issue. As a temporary workaround, consider restricting the use of PFB and TTF files from untrusted sources until a patch is applied.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09641
CVE-2008-1808
DSA-1635-1
DTSA-139-1
RHSA-2008:0556
RHSA-2008:0558
RHSA-2008_0556
RHSA-2009:0329
RHSA-2009_0329

Produtos afetados

Freetype2
Red Hat