CVE-2011-0226: Critical severity freetype vulnerability
Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Type 1 font in a PDF document, as exploited in the wild in July 2011.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0226?
CVE-2011-0226 has a critical severity level, allowing remote code execution and potential denial of service.
How do I fix CVE-2011-0226?
To fix CVE-2011-0226, upgrade to FreeType version 2.4.6 or later, or apply relevant patches provided by your vendor.
What products are affected by CVE-2011-0226?
CVE-2011-0226 affects FreeType versions prior to 2.4.6 and Apple iOS versions before 4.2.9 and 4.3.x before 4.3.4.
What type of attack does CVE-2011-0226 facilitate?
CVE-2011-0226 facilitates remote code execution attacks, which can lead to memory corruption and application crashes.
Who discovered CVE-2011-0226?
CVE-2011-0226 was discovered by security researchers recognizing a signedness error in the FreeType library.