https://seclists.org/oss-sec/2025/q1/212: CVE-2025-27363: out of bounds write in FeType <= 2.13.0
Published Mar 13, 2025
·Updated
Affected Software
1 affected component
FreeType FreeType<=2.13.0
Frequently Asked Questions
1
What is the severity of CVE-2025-27363?
CVE-2025-27363 is classified as a high-severity vulnerability due to its potential for exploitation via out of bounds write conditions.
2
How do I fix CVE-2025-27363?
To fix CVE-2025-27363, upgrade FreeType to version 2.13.1 or later immediately.
3
Which versions of FreeType are affected by CVE-2025-27363?
CVE-2025-27363 affects FreeType versions 2.13.0 and below.
4
What types of files are associated with CVE-2025-27363?
CVE-2025-27363 is related to parsing font subglyph structures in TrueType GX and variable font files.
5
What are the potential impacts of CVE-2025-27363?
The potential impacts of CVE-2025-27363 include application crashes and unintended behavior from out of bounds writes.