CVE-2008-1808: Buffer Overflow
Multiple off-by-one errors in FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via (1) a crafted table in a Printer Font Binary (PFB) file or (2) a crafted SHC instruction in a TrueType Font (TTF) file, which triggers a heap-based buffer overflow.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1808?
CVE-2008-1808 has a critical severity level due to its potential for arbitrary code execution through heap-based buffer overflows.
How do I fix CVE-2008-1808?
To fix CVE-2008-1808, upgrade FreeType to version 2.3.6 or later where the vulnerability is patched.
Which versions of FreeType are affected by CVE-2008-1808?
CVE-2008-1808 affects FreeType versions before 2.3.6, including versions such as 1.3.1, 2.0.6, and 2.3.5.
What types of files can exploit CVE-2008-1808?
CVE-2008-1808 can be exploited using crafted Printer Font Binary (PFB) files or malicious TrueType Font (TTF) files.
Who can exploit CVE-2008-1808?
CVE-2008-1808 can be exploited by context-dependent attackers who can introduce crafted font files to vulnerable systems.