https://seclists.org/oss-sec/2025/q1/216: CVE-2025-27363: out of bounds write in FeType <= 2.13.0
Published Mar 13, 2025
·Updated
Affected Software
1 affected component
FreeType FreeType<=2.13.0
Frequently Asked Questions
1
What is the severity of CVE-2025-27363?
CVE-2025-27363 has a critical severity rating due to the potential for arbitrary code execution from out of bounds writes.
2
How do I fix CVE-2025-27363?
To fix CVE-2025-27363, update to FreeType version 2.14.0 or later where the vulnerability has been addressed.
3
What versions of FreeType are affected by CVE-2025-27363?
CVE-2025-27363 affects FreeType versions up to and including 2.13.0.
4
What are the consequences of exploiting CVE-2025-27363?
Exploiting CVE-2025-27363 can lead to crashes or arbitrary code execution on affected systems.
5
Is there a workaround for CVE-2025-27363?
A temporary workaround for CVE-2025-27363 is to disable features in FreeType that may invoke the vulnerable code until an update can be applied.