FreeType 2.4.1 Memory corruption flaw by processing certain

Risk: Medium
Local: No
Remote: Yes
CWE: CWE-399

CVSS Base Score: 6.8/10
Impact Subscore: 6.4/10
Exploitability Subscore: 8.6/10
Exploit range: Remote
Attack complexity: Medium
Authentication: No required
Confidentiality impact: Partial
Integrity impact: Partial
Availability impact: Partial

A memory corruption flaw was found in the way FreeType font rendering engine processed certain Adobe Type 1 Mac Font File (LWFN) fonts. An attacker could use this flaw to create a specially-crafted font file that, when opened, would cause an application linked against libfreetype to crash, or, possibly execute arbitrary code. Upstream bug report: [1] Public reproducer: [2] Upstream changeset: [3] References: [4] Credit: Robert Swiecki Could you allocate a CVE id for this? Thanks && Regards, Jan.


