https://seclists.org/oss-sec/2025/q1/206: CVE-2025-27363: out of bounds write in FeType <= 2.13.0
Published Mar 12, 2025
·Updated
Affected Software
1 affected component
FreeType<2.13.0
Frequently Asked Questions
1
What is the severity of CVE-2025-27363?
CVE-2025-27363 has been classified as high severity due to the potential for arbitrary code execution.
2
How do I fix CVE-2025-27363?
To fix CVE-2025-27363, update FreeType to version 2.13.1 or later, which addresses the out of bounds write issue.
3
What versions are affected by CVE-2025-27363?
CVE-2025-27363 affects FreeType versions up to and including 2.13.0.
4
What type of vulnerability is CVE-2025-27363?
CVE-2025-27363 is classified as an out of bounds write vulnerability.
5
Can CVE-2025-27363 be exploited remotely?
Yes, CVE-2025-27363 can be exploited remotely if a malicious font file is processed by the application using FreeType.