freetype2

Page content
  • Author: voroskoi
  • Vulnerable: 2.3.4-1terminus1
  • Unaffected: 2.3.4-1terminus2

Victor Stinner has reported a vulnerability in FreeType, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library. The vulnerability is caused due to an error when parsing malformed TTF fonts in src/truetype/ttgload.c and may be exploited when processing a specially crafted TTF font.

CVEs: