« List of all CVEs

CVE-2012-1139

Published: 4/25/2012 Last updated: 8/6/2024 Reserved: 2/14/2012

Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid stack read operation and memory corruption) or possibly execute arbitrary code via crafted glyph data in a BDF font.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (4)

conf-freetype conf-gd conf-mingw-w64-freetype-i686 conf-mingw-w64-freetype-x86_64

Products affected (1)

Product Vendor Version
n/a n/a < 7828309df0f89419a9349761a37c7d1b0da45697

References (92)