Freetype
cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*
- >= 2.13.2, <= 2.13.3
- >= 2.14.0, <= 2.14.1
A vulnerability has been identified in the FreeType library, specifically in versions 2.13.2 and 2.13.3. The issue arises from an integer overflow in the 'tt_var_load_item_variation_store' function, which may lead to an out-of-bounds read when parsing HVAR, VVAR, and MVAR tables in OpenType variable fonts. This vulnerability has been addressed in FreeType version 2.14.2.
Exploitation of this vulnerability could result in out-of-bounds read operations, potentially leading to memory corruption or information disclosure.
Users can upgrade to FreeType version 2.14.2 to address this vulnerability. Instructions for downloading FreeType 2.14.2 are available on the FreeType project page on SourceForge.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.