REDHAT-BUG-2443891: Integer Overflow
An integer overflow in the ttvarloaditemvariationstore function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
freetypeto a version that resolves this vulnerability.Fixed in 2.14.2
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2443891?
The severity of REDHAT-BUG-2443891 is medium (4).
How do I fix REDHAT-BUG-2443891?
To fix REDHAT-BUG-2443891, upgrade to FreeType version 2.14.2 or later.
What is the cause of REDHAT-BUG-2443891?
REDHAT-BUG-2443891 is caused by an integer overflow in the tt_var_load_item_variation_store function of the FreeType library.
In which versions of FreeType is REDHAT-BUG-2443891 present?
REDHAT-BUG-2443891 is present in FreeType versions 2.13.2 and 2.13.3.
What type of vulnerability is REDHAT-BUG-2443891?
REDHAT-BUG-2443891 is classified as an Integer Overflow vulnerability.