Vulnerability Description
Multiple off-by-one errors in FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via (1) a crafted table in a Printer Font Binary (PFB) file or (2) a crafted SHC instruction in a TrueType Font (TTF) file, which triggers a heap-based buffer overflow.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freetype | Freetype | 1.3.1 |
Related Weaknesses (CWE)
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=717
- http://lists.apple.com/archives/security-announce//2008/Sep/msg00003.html
- http://lists.apple.com/archives/security-announce//2008/Sep/msg00004.html
- http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.html
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html
- http://secunia.com/advisories/30600Vendor Advisory
- http://secunia.com/advisories/30721
- http://secunia.com/advisories/30740
- http://secunia.com/advisories/30766
- http://secunia.com/advisories/30819
- http://secunia.com/advisories/30821
- http://secunia.com/advisories/30967
- http://secunia.com/advisories/31479
- http://secunia.com/advisories/31577
FAQ
What is CVE-2008-1808?
CVE-2008-1808 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple off-by-one errors in FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via (1) a crafted table in a Printer Font Binary (PFB) file or (2) a crafted SHC instru...
How severe is CVE-2008-1808?
CVE-2008-1808 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-1808?
Check the references section above for vendor advisories and patch information. Affected products include: Freetype Freetype.