Multiple off-by-one errors in FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via (1) a crafted table in a Printer Font Binary (PFB) file or (2) a crafted SHC instruction in a TrueType Font (TTF) file, which triggers a heap-based buffer overflow.
Vector
NETWORK
Complexity
LOW
Authentication
NONE
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL
Freetype Freetype 2.3.5 * * * (not an official CPE)
Freetype Freetype 2.3.4 * * * (not an official CPE)
Freetype Freetype 2.3.3 * * * (not an official CPE)
Freetype Freetype 2.2.10 * * * (not an official CPE)
Freetype Freetype 2.2.1 * * * (not an official CPE)
Freetype Freetype 2.2.0 * * * (not an official CPE)
Freetype Freetype 2.1.10 * * * (not an official CPE)
Freetype Freetype 2.1.9 * * * (not an official CPE)
Freetype Freetype 2.1.7 * * * (not an official CPE)
Freetype Freetype 2.0.9 * * * (not an official CPE)
Freetype Freetype 2.0.6 * * * (not an official CPE)
Freetype Freetype 1.3.1 * * * (not an official CPE)