CVE-2022-27405: High severity Google Android vulnerability
FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNTSizeRequest.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/freetypeto a version that resolves this vulnerability.Fixed in 2.12.0 - Upgrade
Upgrade
debian/freetypeto a version that resolves this vulnerability.Fixed in 2.10.4+dfsg-1+deb11u1Fixed in 2.10.4+dfsg-1+deb11u2Fixed in 2.12.1+dfsg-5+deb12u3Fixed in 2.12.1+dfsg-5+deb12u4Fixed in 2.13.3+dfsg-1 - Upgrade
Upgrade
freetype/freetypeto a version that resolves this vulnerability.Patch 53dfdcd8198d2b3201a23c4bad9190519ba918db
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue in FreeType?
The vulnerability ID for this security issue in FreeType is CVE-2022-27405.
What is the severity level of CVE-2022-27405?
CVE-2022-27405 has a severity level of high.
What is the affected software for CVE-2022-27405?
The affected software for CVE-2022-27405 includes Google Android, Freetype, and Fedora.
How can the segmentation violation in FreeType be triggered?
The segmentation violation in FreeType can be triggered via the function FNT_Size_Request.
Are there any references available for CVE-2022-27405?
Yes, references for CVE-2022-27405 include https://android.googlesource.com/platform/external/freetype/+/d45f0e49ab54065eb72d92aa3cc5f2152b0910b7 and http://freetype.com.