Remote Code Execution Vulnerability in FreeType Used in Mozilla Firefox Mobile and Other Products
CVE-2012-1130

Currently unrated

Key Information:

Vendor

Freetype

Vendor
CVE Published:
25 April 2012

What is CVE-2012-1130?

A flaw in FreeType prior to version 2.4.9, utilized by Mozilla Firefox Mobile and other applications, could allow remote attackers to exploit crafted PCF font data. This action may lead to a denial of service due to heap memory corruption or potentially allow execution of arbitrary code. Adequate precautions should be undertaken to mitigate risks associated with this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.