REDHAT-BUG-800589: Low severity GNU FreeType vulnerability
An out-of heap-based buffer read flaw was found in the way the anti-aliasing renderer of the FreeType font rendering engine processed certain TrueType fonts. A remote attacker could provide a specially-crafted TrueType font file, which once opened in an application linked against FreeType would lead to that application crash.
Upstream bug report: [1] https://savannah.nongnu.org/bugs/?35604
Upstream patch: [2] http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=fcbc82e69e7b114b0db75e955896107d611898e6
Acknowledgements:
Red Hat would like to thank Mateusz Jurczyk of the Google Security Team for reporting this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-800589?
The severity of REDHAT-BUG-800589 is classified as low.
What is REDHAT-BUG-800589 about?
REDHAT-BUG-800589 describes a heap-based buffer read flaw in the FreeType font rendering engine that could be exploited through specially-crafted TrueType fonts.
Can REDHAT-BUG-800589 be exploited by a remote attacker?
Yes, REDHAT-BUG-800589 can be exploited by a remote attacker providing a malicious TrueType font file.
How do I fix REDHAT-BUG-800589?
To fix REDHAT-BUG-800589, update your GNU FreeType software to the latest version available.
Is REDHAT-BUG-800589 a critical vulnerability?
No, REDHAT-BUG-800589 is considered a low severity vulnerability.