Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-23022

Опубликовано: 10 янв. 2025
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.

A flaw was found in FreeType. In certain versions, specially crafted input may trigger an integer overflow condition. This issue can cause an application crash, leading to a denial of service.

Отчет

No Red Hat products ship an affected version of FreeType.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of OpenJDK 11java-11-openjdk-portableNot affected
Red Hat build of OpenJDK 17java-17-openjdk-portableNot affected
Red Hat build of OpenJDK 21java-21-openjdk-portable-rhel7Not affected
Red Hat Enterprise Linux 10freetypeNot affected
Red Hat Enterprise Linux 10java-21-openjdkNot affected
Red Hat Enterprise Linux 6freetypeNot affected
Red Hat Enterprise Linux 7freetypeNot affected
Red Hat Enterprise Linux 8freetypeNot affected
Red Hat Enterprise Linux 8java-17-openjdkNot affected
Red Hat Enterprise Linux 8java-21-openjdkNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2336955freetype: signed integer overflow in cf2_doFlex

EPSS

Процентиль: 11%
0.00037
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
ubuntu
12 месяцев назад

FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.

CVSS3: 4
nvd
12 месяцев назад

FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.

CVSS3: 4
debian
12 месяцев назад

FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2i ...

suse-cvrf
8 месяцев назад

Security update for freetype2

CVSS3: 4
github
12 месяцев назад

FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.

EPSS

Процентиль: 11%
0.00037
Низкий

5.5 Medium

CVSS3