First published: Sat Oct 12 2019(Updated: )
It was discovered that the FreetypeFontScaler class in the 2D component in OpenJDK did not perform checks dimension of glyph bitmap images read from font files. A specially crafted font file could use this flaw to cause a Java application to crash when processing glyph images of excessive size.
Affected Software | Affected Version | How to fix |
---|---|---|
OpenJDK 8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1761149 is typically classified as moderate due to the potential for application crashes.
To fix REDHAT-BUG-1761149, you should update to a patched version of Oracle OpenJDK that addresses this vulnerability.
REDHAT-BUG-1761149 can cause Java applications to crash if they process malformed glyph bitmap images from specially crafted font files.
Yes, if a Java application handles untrusted font files and is vulnerable to REDHAT-BUG-1761149, it can be exploited in a production environment.
REDAHT-BUG-1761149 affects OpenJDK 17 and potentially other versions that utilize the FreetypeFontScaler class.