CVE-2012-5668: Buffer Overflow
Published Jan 24, 2013
·Updated
FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to BDF fonts and the improper handling of an "allocation error" in the bdffreefont function.
Affected Software
47 affected components
FreeType<=2.4.10
FreeType=1.3.1
FreeType=2.0.0
FreeType=2.0.1
FreeType=2.0.2
FreeType=2.0.3
FreeType=2.0.4
FreeType=2.0.5
FreeType=2.0.6
FreeType=2.0.7
FreeType=2.0.8
FreeType=2.0.9
FreeType=2.1
FreeType=2.1.3
FreeType=2.1.4
FreeType=2.1.5
FreeType=2.1.6
FreeType=2.1.7
FreeType=2.1.8
FreeType=2.1.8-rc1
FreeType=2.1.9
FreeType=2.1.10
FreeType=2.2.0
FreeType=2.2.1
FreeType=2.3.0
FreeType=2.3.1
FreeType=2.3.2
FreeType=2.3.3
FreeType=2.3.4
FreeType=2.3.5
FreeType=2.3.6
FreeType=2.3.7
FreeType=2.3.8
FreeType=2.3.9
FreeType=2.3.10
FreeType=2.3.11
FreeType=2.3.12
FreeType=2.4.0
FreeType=2.4.1
FreeType=2.4.2
FreeType=2.4.3
FreeType=2.4.4
FreeType=2.4.5
FreeType=2.4.6
FreeType=2.4.7
FreeType=2.4.8
FreeType=2.4.9
Event History
Jan 24, 2013
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-5668?
CVE-2012-5668 has a severity rating of medium due to its potential to cause a denial of service.
2
How does CVE-2012-5668 affect FreeType applications?
CVE-2012-5668 can cause FreeType applications to crash due to a NULL pointer dereference when handling BDF fonts.
3
How do I fix CVE-2012-5668?
To fix CVE-2012-5668, upgrade to FreeType version 2.4.11 or later.
4
What versions of FreeType are affected by CVE-2012-5668?
CVE-2012-5668 affects all FreeType versions prior to 2.4.11.
5
Can CVE-2012-5668 be exploited remotely?
Yes, CVE-2012-5668 can be exploited by an attacker who can send specifically crafted BDF font data to an application using FreeType.