First published: Tue Feb 13 2018(Updated: )
An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ttinterp.c could lead to DoS via a crafted font file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/freetype | <2.8-0.2ubuntu2.1 | 2.8-0.2ubuntu2.1 |
<=2.9 | ||
=17.10 | ||
Freetype Freetype | <=2.9 | |
Canonical Ubuntu Linux | =17.10 | |
debian/freetype | 2.9.1-3+deb10u3 2.9.1-3+deb10u2 2.10.4+dfsg-1+deb11u1 2.12.1+dfsg-5 2.13.2+dfsg-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2018-6942.
The severity rating of CVE-2018-6942 is medium with a value of 6.5.
The affected software is FreeType 2 through 2.9.
The vulnerability can be exploited by using a crafted font file.
Yes, there are remedies available for the vulnerability, depending on the affected software version. Please refer to the references for specific remedies.