REDHAT-BUG-800600: Low severity GNU FreeType vulnerability
An out-of heap-based buffer read flaw was found in the way auxiliary PostScript driver of the FreeType font rendering engine performed conversion of certain PostScript font objects. A remote attacker could provide a specially-crafted PostScript font file, which once opened in an application linked against FreeType would lead to that application crash.
Upstream bug report: [1] https://savannah.nongnu.org/bugs/?35657
Upstream patch: [2] http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=292144b44a15c1a72f2ef76475d65b7a3a3fba67
Acknowledgements:
Red Hat would like to thank Mateusz Jurczyk of the Google Security Team for reporting this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-800600?
The severity of REDHAT-BUG-800600 is considered low.
How do I fix REDHAT-BUG-800600?
To fix REDHAT-BUG-800600, update the GNU FreeType to the latest version that addresses this vulnerability.
What type of vulnerability is REDHAT-BUG-800600?
REDHAT-BUG-800600 is a heap-based buffer read flaw related to the FreeType font rendering engine.
Can REDHAT-BUG-800600 be exploited remotely?
Yes, a remote attacker can exploit REDHAT-BUG-800600 by providing a specially-crafted PostScript font file.
Which software is affected by REDHAT-BUG-800600?
The affected software for REDHAT-BUG-800600 is the GNU FreeType font rendering engine.