Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-2004

Опубликовано: 14 нояб. 2022
Источник: redhat
CVSS3: 0

Описание

An integer overflow vulnerability was discovered in Freetype in tt_hvadvance_adjust() function in src/truetype/ttgxvar.c. This flaw causes an application to crash or leads to a denial of service.

Отчет

Red Hat Product Security does not consider this to be a vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of OpenJDK 1.8java-11-openjdk-portableAffected
Red Hat Enterprise Linux 6freetypeOut of support scope
Red Hat Enterprise Linux 7freetypeOut of support scope
Red Hat Enterprise Linux 8freetypeWill not fix
Red Hat Enterprise Linux 8java-11-openjdkAffected
Red Hat Enterprise Linux 8java-17-openjdkAffected
Red Hat Enterprise Linux 9freetypeWill not fix
Red Hat Enterprise Linux 9java-11-openjdkAffected
Red Hat Enterprise Linux 9java-17-openjdkAffected
Red Hat Enterprise Linux 9libreoffice:flatpak/java-11-openjdkNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2186428freetype: integer overflowin in tt_hvadvance_adjust() in src/truetype/ttgxvar.c

0 Low

CVSS3

Связанные уязвимости

ubuntu
почти 3 года назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

nvd
почти 3 года назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

CVSS3: 7.5
msrc
почти 3 года назад

Описание отсутствует

suse-cvrf
больше 2 лет назад

Security update for freetype2

CVSS3: 7.5
github
почти 3 года назад

An integer overflow vulnerability was discovered in Freetype in tt_hvadvance_adjust() function in src/truetype/ttgxvar.c.

0 Low

CVSS3