Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
2009-04-17T00:30:00.250
2025-04-09T00:30:58.490
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | freetype | freetype | ≤ 2.3.9 | Yes |
Operating System | debian | debian_linux | 4.0 | Yes |
Operating System | debian | debian_linux | 5.0 | Yes |
Operating System | debian | debian_linux | 6.0 | Yes |
Operating System | canonical | ubuntu_linux | 6.06 | Yes |
Operating System | canonical | ubuntu_linux | 8.04 | Yes |
Operating System | canonical | ubuntu_linux | 8.10 | Yes |
Operating System | canonical | ubuntu_linux | 9.04 | Yes |
Operating System | opensuse | opensuse | 10.3 | Yes |
Operating System | opensuse | opensuse | 11.0 | Yes |
Operating System | opensuse | opensuse | 11.1 | Yes |
Operating System | suse | linux_enterprise_server | 10 | Yes |
Operating System | suse | linux_enterprise_server | 11 | Yes |
Application | apple | safari | 4.0 | Yes |
Operating System | apple | iphone_os | ≤ 2.2.1 | Yes |
Operating System | apple | mac_os_x | ≤ 10.6.4 | Yes |
Operating System | apple | mac_os_x | 10.4.11 | Yes |
Operating System | apple | mac_os_x | 10.5.8 | Yes |
Operating System | apple | mac_os_x_server | ≤ 10.6.4 | Yes |
Operating System | apple | mac_os_x_server | 10.4.11 | Yes |
Operating System | apple | mac_os_x_server | 10.5.8 | Yes |