CVE-2018-6942: Null Pointer Dereference
Published Feb 13, 2018
·Updated
An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the InsGETVARIATION() function within ttinterp.c could lead to DoS via a crafted font file.
Affected Software
3 affected componentsFixes available
FreeType FreeType<=2.9
Canonical Ubuntu Linux=17.10
debian/freetype
2.10.4+dfsg-1+deb11u12.10.4+dfsg-1+deb11u22.12.1+dfsg-5+deb12u42.13.3+dfsg-12.14.1+dfsg-2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/freetypeto a version that resolves this vulnerability.Fixed in 2.10.4+dfsg-1+deb11u1Fixed in 2.10.4+dfsg-1+deb11u2Fixed in 2.12.1+dfsg-5+deb12u4Fixed in 2.13.3+dfsg-1Fixed in 2.14.1+dfsg-2
Event History
Feb 13, 2018
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Data Sourced
via NVD·05:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:09 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·08:44 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·08:44 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-6942.
2
What is the severity rating of CVE-2018-6942?
The severity rating of CVE-2018-6942 is medium with a value of 6.5.
3
What is the affected software?
The affected software is FreeType 2 through 2.9.
4
How can the vulnerability be exploited?
The vulnerability can be exploited by using a crafted font file.
5
Is there a fix available for CVE-2018-6942?
Yes, there are remedies available for the vulnerability, depending on the affected software version. Please refer to the references for specific remedies.