CVE-2025-23022: Integer Overflow
Published Jan 10, 2025
·Updated
FreeType 2.8.1 has a signed integer overflow in cf2doFlex in cff/cf2intrp.c.
Affected Software
1 affected component
FreeType=2.8.1
Event History
Jan 10, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Jan 13, 2025
Data Sourced
via Debian·10:09 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-23022?
CVE-2025-23022 is classified as a high severity vulnerability due to its potential for exploitation through signed integer overflow.
2
How do I fix CVE-2025-23022?
To fix CVE-2025-23022, it is recommended to upgrade FreeType from version 2.8.1 to a patched version released by the maintainers.
3
What systems are affected by CVE-2025-23022?
CVE-2025-23022 specifically affects FreeType version 2.8.1.
4
What are the risks associated with CVE-2025-23022?
The risks associated with CVE-2025-23022 include potential remote code execution or denial of service due to the signed integer overflow vulnerability.
5
Is there a workaround for CVE-2025-23022?
Currently, there are no known effective workarounds for CVE-2025-23022, and upgrading to a secure version is the best option.