Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23081
HistoryApr 10, 2020 - 12:15 a.m.

Denial Of Service (DoS)

2020-04-1000:15:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.05 Low

EPSS

Percentile

92.9%

FreeType is vulnerable to denial of service (DoS). An integer overflow flaw was found in the way the FreeType font engine processed BDF font files. If a user loaded a carefully crafted font file with a program linked against FreeType, it could cause the application to crash or execute arbitrary code. While it is uncommon for a user to explicitly load a font file, there are several application file formats which contain embedded fonts that are parsed by FreeType.

References