Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3970
HistoryApr 26, 2017 - 4:43 a.m.

Out-of-Bounds Write

2017-04-2604:43:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.009 Low

EPSS

Percentile

83.1%

freetype is vulnerable to an out-of-bounds write. A malicious user can pass a cff font file to the application to cause a heap-based buffer overflow that can lead to an out-of-bounds write. This can cause the application to crash or overwrite values in the heap.

CPENameOperatorVersion
freetypele2.6.4
freetypele2.7.0.1