CVE-2007-3506: High severity FreeType vulnerability
Published Jul 2, 2007
·Updated
The ftbitmapassurebuffer function in src/base/ftbimap.c in FreeType 2.3.3 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors involving bitmap fonts, related to a "memory buffer overwrite bug."
Affected Software
1 affected component
FreeType<=2.3.3
Remediation
Event History
Jul 2, 2007
CVE Published
07:30 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3506?
CVE-2007-3506 has a high severity rating due to its potential for denial of service and arbitrary code execution.
2
How do I fix CVE-2007-3506?
To fix CVE-2007-3506, upgrade FreeType to version 2.3.4 or later.
3
What software is affected by CVE-2007-3506?
CVE-2007-3506 affects FreeType versions up to and including 2.3.3.
4
What type of attack does CVE-2007-3506 allow?
CVE-2007-3506 allows context-dependent attackers to cause a denial of service and potentially execute arbitrary code.
5
Where in the FreeType source code does CVE-2007-3506 exist?
CVE-2007-3506 exists in the ft_bitmap_assure_buffer function in src/base/ftbimap.c.