Denial of Service and Memory Corruption Vulnerability in FreeType Used by Mozilla Firefox Mobile and Other Products
CVE-2012-1131

Currently unrated

Key Information:

Vendor

Freetype

Vendor
CVE Published:
25 April 2012

What is CVE-2012-1131?

The vulnerability in FreeType, affecting versions prior to 2.4.9, can be exploited on 64-bit platforms. It allows attackers to launch a denial of service attack through invalid heap read operations and potential memory corruption. This vulnerability can occur when processing specific vector formats associated with the cell table of a font, thereby jeopardizing the security and stability of applications that rely on FreeType, including Mozilla Firefox Mobile.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.