Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-23022

Опубликовано: 10 янв. 2025
Источник: redhat
CVSS3: 5.5

Описание

FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.

A flaw was found in FreeType. In certain versions, specially crafted input may trigger an integer overflow condition. This issue can cause an application crash, leading to a denial of service.

Отчет

No Red Hat products ship an affected version of FreeType.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of OpenJDK 11java-11-openjdk-portableNot affected
Red Hat build of OpenJDK 17java-17-openjdk-portableNot affected
Red Hat build of OpenJDK 21java-21-openjdk-portable-rhel7Not affected
Red Hat Enterprise Linux 10freetypeNot affected
Red Hat Enterprise Linux 10java-21-openjdkNot affected
Red Hat Enterprise Linux 6freetypeNot affected
Red Hat Enterprise Linux 7freetypeNot affected
Red Hat Enterprise Linux 8freetypeNot affected
Red Hat Enterprise Linux 8java-17-openjdkNot affected
Red Hat Enterprise Linux 8java-21-openjdkNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2336955freetype: signed integer overflow in cf2_doFlex

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
ubuntu
около 1 года назад

FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.

CVSS3: 4
nvd
около 1 года назад

FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.

CVSS3: 4
debian
около 1 года назад

FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2i ...

suse-cvrf
9 месяцев назад

Security update for freetype2

CVSS3: 4
github
около 1 года назад

FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.

5.5 Medium

CVSS3