PT-2008-1133 · Freetype+1 · Freetype2+1

Published

2008-06-16

·

Updated

2021-01-26

·

CVE-2008-1808

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FreeType2 versions prior to 2.3.6
Description The issue involves multiple off-by-one errors that can be exploited by context-dependent attackers to execute arbitrary code. This can be achieved through a crafted table in a Printer Font Binary (PFB) file or a crafted SHC instruction in a TrueType Font (TTF) file, leading to a heap-based buffer overflow. The exploitation of these vulnerabilities may compromise the confidentiality, integrity, and availability of protected information and can be performed remotely.
Recommendations For FreeType2 versions prior to 2.3.6, update to version 2.3.6 or later to resolve the issue. As a temporary workaround, consider restricting the use of PFB and TTF files from untrusted sources until a patch is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09641
CVE-2008-1808
DSA-1635-1
DTSA-139-1
RHSA-2008:0556
RHSA-2008:0558
RHSA-2008_0556
RHSA-2009:0329
RHSA-2009_0329

Affected Products

Freetype2
Red Hat