CVE-2008-1807
FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via an invalid "number of axes" field in a Printer Font Binary (PFB) file, which triggers a free of arbitrary memory locations, leading to memory corruption.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.58%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via an invalid "number of axes" field in a Printer Font Binary (PFB) file, which triggers a free of arbitrary memory locations, leading to memory corruption.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 3.58% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- freetype/freetype
- Source
- cve@mitre.org
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=716
- http://lists.apple.com/archives/security-announce//2008/Sep/msg00003.html
- http://lists.apple.com/archives/security-announce//2008/Sep/msg00004.html
- http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.html
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html
- http://secunia.com/advisories/30600Vendor Advisory
- http://secunia.com/advisories/30721
- http://secunia.com/advisories/30740
- http://secunia.com/advisories/30766
- http://secunia.com/advisories/30819
- http://secunia.com/advisories/30821
- http://secunia.com/advisories/30967
- http://secunia.com/advisories/31479
- http://secunia.com/advisories/31577
- http://secunia.com/advisories/31707
- http://secunia.com/advisories/31709
- http://secunia.com/advisories/31711
- http://secunia.com/advisories/31712
- http://secunia.com/advisories/31823
- http://secunia.com/advisories/31856
- http://secunia.com/advisories/31900
- http://secunia.com/advisories/33937
- http://security.gentoo.org/glsa/glsa-200806-10.xml
- http://security.gentoo.org/glsa/glsa-201209-25.xml
- http://securitytracker.com/id?1020239
- http://sourceforge.net/project/shownotes.php?group_id=3157&release_id=605780
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-239006-1
- http://support.apple.com/kb/HT3026
- http://support.apple.com/kb/HT3129
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.