Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4024
HistoryApr 27, 2017 - 10:11 p.m.

Heap Based Buffer Overflow

2017-04-2722:11:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.009 Low

EPSS

Percentile

83.3%

FreeType is vulnerable to out-of-bounds write issues. These writes are caused by a heap-based buffer overflow in the t1_builder_close_contour function in psaux/psobjs.c. If a malformed font is supplied, it is possible that the contour variable is started but no points added, causing the buffer overflow.