« List of all CVEs

CVE-2011-0226

Published: 7/19/2011 Last updated: 8/6/2024 Reserved: 12/23/2010

Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Type 1 font in a PDF document, as exploited in the wild in July 2011.

CNA assigner: apple (286789f9-fbc2-4510-9f9a-43facdede74c) Requested by: n/a

Opam packages affected (4)

conf-freetype conf-gd conf-mingw-w64-freetype-i686 conf-mingw-w64-freetype-x86_64

Products affected (1)

Product Vendor Version
n/a n/a < d00e4125680f7074c4f42ce3c297336f23128e70

References (80)