FreeType - '.TTF' File Remote Buffer Overflow
Author: Josh Bressers
type: remote
platform: unix
port:
date_added: 2006-06-08
date_updated: 2013-09-17
verified: 1
codes: CVE-2006-0747;OSVDB-26032
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/18326/info
FreeType is prone to a buffer-overflow vulnerability. This issue is due to an integer-underflow that results in a buffer being overrun with attacker-supplied data.
This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library. Failed exploit attempts will likely crash applications, denying service to legitimate users.
FreeType versions prior to 2.2.1 are vulnerable to this issue.
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/27992.zip