REDHAT-BUG-800585: Low severity GNU FreeType vulnerability

Published Mar 6, 2012
·
Updated

An out-of heap-based buffer read flaw was found in the way Type42 font parser of the FreeType font rendering engine performed parsing of certain special font name table (SFNT) strings. A remote attacker could provide a specially-crafted font file, which once opened in an application linked against FreeType would lead to that application crash.

Upstream bug report: [1] https://savannah.nongnu.org/bugs/?35602

Upstream patch: [2] http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=82365c0dead99dd119d9e7117cf4f36ce1d1cbe1

Affected Software

1 affected component
GNU FreeType

Event History

Mar 6, 2012
Data Sourced
06:48 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-800585?

The severity of REDHAT-BUG-800585 is classified as a medium to high risk due to potential exploitation by remote attackers.

2

How do I fix REDHAT-BUG-800585?

To fix REDHAT-BUG-800585, it is recommended to update to the latest version of the GNU FreeType library that addresses the vulnerability.

3

What causes REDHAT-BUG-800585?

REDHAT-BUG-800585 is caused by a flaw in the Type42 font parser within the FreeType font rendering engine when parsing certain special font name table strings.

4

Can REDHAT-BUG-800585 be exploited remotely?

Yes, REDHAT-BUG-800585 can be exploited remotely if an attacker delivers a specially crafted font file to a vulnerable application.

5

What applications are affected by REDHAT-BUG-800585?

Applications linked against the affected version of the GNU FreeType library are vulnerable to REDHAT-BUG-800585 when handling certain font files.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203