CVE-2022-27405
published 2022-04-22CVE-2022-27405: FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.82%
85.0th percentile
FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freetype | < freetype 2.11.1+dfsg-2 (bookworm) | freetype 2.11.1+dfsg-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| freetype | freetype | < 2.12.0 | 2.12.0 |
| freetype | freetype | >= 0 < 2.10.4+dfsg-1+deb11u1 | 2.10.4+dfsg-1+deb11u1 |
| freetype | freetype | >= 0 < 2.11.1+dfsg-2 | 2.11.1+dfsg-2 |
| freetype | freetype | >= 0 < 2.11.1+dfsg-2 | 2.11.1+dfsg-2 |
| freetype | freetype | >= 0 < 2.11.1+dfsg-2 | 2.11.1+dfsg-2 |
| android | — | — | |
| msrc | cbl2_freetype_2.12.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_freetype_2.12.1-1_on_cbl_mariner_1.0 | — | — |
| platform | external_freetype | >= 11:0 < 11:2023-07-01 | 11:2023-07-01 |
| platform | external_freetype | >= 12:0 < 12:2023-07-01 | 12:2023-07-01 |
| platform | external_freetype | >= 12L:0 < 12L:2023-07-01 | 12L:2023-07-01 |
| platform | external_freetype | >= 13:0 < 13:2023-07-01 | 13:2023-07-01 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens RUGGEDCOM APE1808 Product Family
cisa_ics·2023-09-14
Siemens RUGGEDCOM APE1808 Product Family
ICS Advisory
##
Siemens RUGGEDCOM APE1808 Product Family
Release DateSeptember 14, 2023
Alert CodeICSA-23-257-04
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.2
- ATTENTION: Low Attack Complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM APE1808 Product Family
- Vulnerabilities: Exposure of Sensitive Information to an Unauthorized Actor, Buffer Underflow, Classic Buffer Overflow, Time-of-check Time-of-use Race Condition, Out-of-bounds Read, Im
Android
CVE-2022-27405: Android Security Bulletin 2023-07-01
CVE: CVE-2022-27405
Severity: HIGH
Type: ID
Affected AOSP versions: 11, 12, 12L, 13
References: A-271680254
vendor_android·2023-07-01·CVSS 7.5
CVE-2022-27405 [HIGH] CVE-2022-27405: Android Security Bulletin 2023-07-01
CVE: CVE-2022-27405
Severity: HIGH
Type: ID
Affected AOSP versions: 11, 12, 12L, 13
References: A-271680254
Android Security Bulletin 2023-07-01
CVE: CVE-2022-27405
Severity: HIGH
Type: ID
Affected AOSP versions: 11, 12, 12L, 13
References: A-271680254
Ubuntu
FreeType vulnerabilities
vendor_ubuntu·2022-07-20
CVE-2022-27405 FreeType vulnerabilities
Title: FreeType vulnerabilities
Summary: Several security issues were fixed in FreeType.
It was discovered that FreeType did not correctly handle certain malformed
font files. If a user were tricked into using a specially crafted font
file, a remote attacker could cause FreeType to crash, or possibly execute
arbitrary code.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
FreeType: Segmentation violation via FNT_Size_Request
vendor_redhat·2022-04-22·CVSS 7.5
CVE-2022-27405 [HIGH] CWE-824 FreeType: Segmentation violation via FNT_Size_Request
FreeType: Segmentation violation via FNT_Size_Request
FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.
A segmentation fault was found in the FreeType library. This flaw allows an attacker to attempt access to a memory location in a way that could cause an application to halt or crash, leading to a denial of service.
Package: prometheus-container (Red Hat Advanced Cluster Management for Kubernetes 2) - Not affected
Package: freetype (Red Hat Enterprise Linux 6) - Not affected
Package: freetype (Red Hat Enterprise Linux 7) - Out of support scope
Microsoft
FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.
vendor_msrc·2022-04-12·CVSS 7.5
CVE-2022-27405 [HIGH] CWE-125 FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.
FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Cus
Debian
CVE-2022-27405: freetype - FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to conta...
vendor_debian·2022·CVSS 7.5
CVE-2022-27405 [HIGH] CVE-2022-27405: freetype - FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to conta...
FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.
Scope: local
bookworm: resolved (fixed in 2.11.1+dfsg-2)
bullseye: resolved (fixed in 2.10.4+dfsg-1+deb11u1)
forky: resolved (fixed in 2.11.1+dfsg-2)
sid: resolved (fixed in 2.11.1+dfsg-2)
trixie: resolved (fixed in 2.11.1+dfsg-2)
OSV
CVE-2022-27405: In ft_open_face_internal of ftobjs
osv·2023-07-01
CVE-2022-27405 CVE-2022-27405: In ft_open_face_internal of ftobjs
In ft_open_face_internal of ftobjs.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA
GHSA-3p63-23m4-gmcp: FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request
ghsa_unreviewed·2022-04-23
CVE-2022-27405 [HIGH] CWE-125 GHSA-3p63-23m4-gmcp: FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request
FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.
OSV
CVE-2022-27405: FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request
osv·2022-04-22·CVSS 7.5
CVE-2022-27405 [HIGH] CVE-2022-27405: FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request
FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.freedesktop.org/freetype/freetype/-/issues/1139https://lists.fedoraproject.org/archives/list/[email protected]/message/EFPNRKDLCXHZVYYQLQMP44UHLU32GA6Z/https://lists.fedoraproject.org/archives/list/[email protected]/message/FDU2FOEMCEF6WVR6ZBIH5MT5O7FAK6UP/https://lists.fedoraproject.org/archives/list/[email protected]/message/IWQ7IB2A75MEHM63WEUXBYEC7OR5SGDY/https://lists.fedoraproject.org/archives/list/[email protected]/message/NYVC2NPKKXKP3TWJWG4ONYWNO6ZPHLA5/https://lists.fedoraproject.org/archives/list/[email protected]/message/TCEMWCM46PKM4U5ENRASPKQD6JDOLKRU/https://security.gentoo.org/glsa/202402-06https://gitlab.freedesktop.org/freetype/freetype/-/issues/1139https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EFPNRKDLCXHZVYYQLQMP44UHLU32GA6Z/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FDU2FOEMCEF6WVR6ZBIH5MT5O7FAK6UP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IWQ7IB2A75MEHM63WEUXBYEC7OR5SGDY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NYVC2NPKKXKP3TWJWG4ONYWNO6ZPHLA5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TCEMWCM46PKM4U5ENRASPKQD6JDOLKRU/https://security.gentoo.org/glsa/202402-06
2022-04-22
Published