CVE-2008-1808

Published: 06/16/2008 19:41:00
Multiple off-by-one errors in FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via (1) a crafted table in a Printer Font Binary (PFB) file or (2) a crafted SHC instruction in a TrueType Font (TTF) file, which triggers a heap-based buffer overflow.
HIGH
CVSS v2: 7.5

Status

DocFilters Release Package State Justification Comment
25.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
24.4 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
24.4.0 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
24.3 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
24.2.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
24.2 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
24.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
23.3 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
23.2.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
23.2 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
23.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
22.4 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
22.3 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
22.2 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
22.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
21.11.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
21.11 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
21.8.1 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.
21.8 freetype (2.6.5) Not Affected Code Not Present 2.6.5 does not match CVE configuration.

Severity score breakdown

References