CVE-2008-1807: High severity freetype vulnerability
Published Jun 16, 2008
·Updated
FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via an invalid "number of axes" field in a Printer Font Binary (PFB) file, which triggers a free of arbitrary memory locations, leading to memory corruption.
Affected Software
4 affected components
FreeType=2.3.4
FreeType=2.3.5
FreeType=1.3.1
FreeType=2.3.3
Event History
Jun 16, 2008
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1807?
CVE-2008-1807 is considered to have a high severity due to the potential for arbitrary code execution.
2
How do I fix CVE-2008-1807?
To fix CVE-2008-1807, upgrade to FreeType version 2.3.6 or later.
3
What types of systems are affected by CVE-2008-1807?
CVE-2008-1807 affects FreeType versions 1.3.1, 2.3.3, 2.3.4, and 2.3.5.
4
What are the consequences of exploiting CVE-2008-1807?
Exploitation of CVE-2008-1807 can lead to memory corruption and execution of arbitrary code.
5
Who can exploit the vulnerability in CVE-2008-1807?
CVE-2008-1807 can be exploited by context-dependent attackers using specially crafted Printer Font Binary files.