REDHAT-BUG-621980: Buffer Overflow
An array index error, leading to heap-based buffer overflow was found in the way the FreeType font rendering engine processed FontType42 font files with negative length of certain special font name table strings. An attacker could use this flaw to create a specially-crafted font file (which bypasses a size check and triggers a heap-based buffer overflow). Such file, when opened, would cause an application linked against libfreetype to crash, or, possibly execute arbitrary code.
Upstream bug report: [1] https://savannah.nongnu.org/bugs/?30656 Public reproducer: [2] http://alt.swiecki.net/j/f/sigsegv29.ttf Upstream changeset: [3] http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=c06da1ad34663da7b6fc39b030dc3ae185b96557
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-621980?
The severity of REDHAT-BUG-621980 is classified as high with a rating of 7.
How do I fix REDHAT-BUG-621980?
To fix REDHAT-BUG-621980, ensure you update your GNU FreeType software to a version that has patched this vulnerability.
What type of vulnerability is REDHAT-BUG-621980?
REDHAT-BUG-621980 is a buffer overflow vulnerability caused by an array index error in the FreeType font rendering engine.
What impact can REDHAT-BUG-621980 have on my system?
An attacker can exploit REDHAT-BUG-621980 by creating a specially-crafted font file that can lead to a heap-based buffer overflow, potentially allowing arbitrary code execution.
Which software is affected by REDHAT-BUG-621980?
REDHAT-BUG-621980 affects the GNU FreeType font rendering engine.