4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:N/A:P
0.011 Low
EPSS
Percentile
84.5%
The _bdf_parse_glyphs function in FreeType before 2.4.11 allows
context-dependent attackers to cause a denial of service (out-of-bounds
write and crash) via vectors related to BDF fonts and an ENCODING field
with a negative value.
Author | Note |
---|---|
mdeslaur | introduced by http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/src/bdf/bdflib.c?id=03242f58c4bf7226276d8e4e7cb106045319e517 so only in 2.4.9+ |