CVE-2011-3256Code Injection in Freetype

Severity
4.3MEDIUMNVD
OSV9.3
EPSS
3.2%
top 12.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14
Latest updateMay 17

Description

FreeType 2 before 2.4.7, as used in CoreGraphics in Apple iOS before 5, Mandriva Enterprise Server 5, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font, a different vulnerability than CVE-2011-0226.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/freetype< freetype 2.4.7-1 (bookworm)
Debianfreetype/freetype< 2.4.7-1+3
NVDapple/iphone_os19 versions+18

🔴Vulnerability Details

2
GHSA
GHSA-mjq4-j36x-7h6p: FreeType 2 before 22022-05-17
OSV
CVE-2011-3256: FreeType 2 before 22011-10-14

📋Vendor Advisories

3
Ubuntu
FreeType vulnerabilities2011-11-18
Red Hat
freetype: FT_Bitmap_New integer overflow, FreeType TT_Vary_Get_Glyph_Deltas improper input validation2011-10-12
Debian
CVE-2011-3256: freetype - FreeType 2 before 2.4.7, as used in CoreGraphics in Apple iOS before 5, Mandriva...2011

💬Community

3
Bugzilla
CVE-2011-3256 FreeType FT_Bitmap_New integer overflow to buffer overflow, FreeType TT_Vary_Get_Glyph_Deltas improper input validation [fedora-all]2011-10-26
Bugzilla
CVE-2011-3256 freetype: FT_Bitmap_New integer overflow to buffer overflow, FreeType TT_Vary_Get_Glyph_Deltas improper input validation [fedora-16]2011-10-26
Bugzilla
CVE-2011-3256 freetype: FT_Bitmap_New integer overflow, FreeType TT_Vary_Get_Glyph_Deltas improper input validation2011-10-14
CVE-2011-3256 — Code Injection in Debian Freetype | cvebase