vendor:
FreeType
by:
SecurityFocus
7.5
CVSS
HIGH
Denial-of-Service
476
CWE
Product Name: FreeType
Affected Version From: Prior to 2.2.1
Affected Version To: 2.2.2001
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
FreeType Denial-of-Service Vulnerability
FreeType is prone to a denial-of-service vulnerability. This issue is due to a flaw in the library that causes a NULL-pointer dereference. This issue allows remote attackers to crash applications that use the affected library, denying service to legitimate users.
Mitigation:
Upgrade to FreeType version 2.2.1 or later.