Denial of Service and Code Execution Flaw in FreeType Affecting Mozilla Firefox Mobile
CVE-2012-1128

Currently unrated

Key Information:

Vendor

Freetype

Vendor
CVE Published:
25 April 2012

What is CVE-2012-1128?

FreeType versions before 2.4.9 are susceptible to a vulnerability that allows remote attackers to initiate a denial of service through NULL pointer dereference and memory corruption. This may lead to the execution of arbitrary code when a specially crafted TrueType font is processed, affecting Mozilla Firefox Mobile and various other software products relying on FreeType for font rendering.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.