REDHAT-BUG-800597: Low severity GNU FreeType vulnerability
An out-of heap-based buffer read flaw was found in the way TrueType bytecode / opcode interpreter of FreeType font rendering engine executed the 'Move Indirect Relative Point' (MIRP) instruction. A remote attacker could provide a specially-crafted font file, which once opened in an application linked against FreeType would lead to that application crash.
Upstream bug report: [1] https://savannah.nongnu.org/bugs/?35646
Upstream patch: [2] http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=a33c013fe2dc6e65de2879682201d9c155292349
Acknowledgements:
Red Hat would like to thank Mateusz Jurczyk of the Google Security Team for reporting this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-800597?
The severity of REDHAT-BUG-800597 is rated as low.
How do I fix REDHAT-BUG-800597?
To fix REDHAT-BUG-800597, ensure that you are using an updated version of the FreeType font rendering engine that addresses this vulnerability.
What type of vulnerability is REDHAT-BUG-800597?
REDHAT-BUG-800597 is a heap-based buffer read flaw related to the TrueType bytecode interpreter in FreeType.
What could an attacker achieve by exploiting REDHAT-BUG-800597?
An attacker could potentially craft a malicious font file that triggers the vulnerability when opened in an application, leading to security risks.
Which software is affected by REDHAT-BUG-800597?
GNU FreeType is the software affected by the vulnerability identified as REDHAT-BUG-800597.