Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24135
HistoryApr 10, 2020 - 12:47 a.m.

Arbitrary Code Execution

2020-04-1000:47:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

0.513 Medium

EPSS

Percentile

97.6%

freetype is vulnerable to arbitrary code execution. Two stack overflow flaws were found in the way the FreeType font engineprocessed certain Compact Font Format (CFF) character strings (opcodes). If a user loaded a specially-crafted font file with an application linked against FreeType, it could cause the application to crash or, possibly, execute arbitrary code with the privileges of the user running the application.

References