CVE-2022-27404: Buffer Overflow
Published Apr 22, 2022
·Updated
FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfntinitface.
Affected Software
6 affected componentsFixes available
redhat/freetype<2.12.0
2.12.0
FreeType<2.12.0
fedoraproject fedora=34
fedoraproject fedora=35
fedoraproject fedora=36
debian/freetype
2.10.4+dfsg-1+deb11u12.10.4+dfsg-1+deb11u22.12.1+dfsg-5+deb12u32.12.1+dfsg-5+deb12u42.13.3+dfsg-1
Remediation
Event History
Apr 22, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Mar 22, 2025
Data Sourced
via Ubuntu·01:55 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·01:56 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-27404.
2
What is the severity of CVE-2022-27404?
The severity of CVE-2022-27404 is critical with a score of 9.8.
3
What software is affected by CVE-2022-27404?
The software affected by CVE-2022-27404 includes FreeType (up to version 2.12.0) and Fedora (versions 34, 35, 36).
4
What is the CWE ID associated with CVE-2022-27404?
The CWE ID associated with CVE-2022-27404 is CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-787 (Out-of-bounds Write).
5
How can I fix the vulnerability CVE-2022-27404?
To fix the vulnerability CVE-2022-27404, it is recommended to update FreeType to a version above 2.12.0 and apply the necessary patches provided by the vendor.