Memory Corruption Vulnerability in FreeType Library for Multiple Products
CVE-2012-1138

Currently unrated

Key Information:

Vendor

Freetype

Vendor
CVE Published:
25 April 2012

What is CVE-2012-1138?

The FreeType library prior to version 2.4.9, used in several products including Mozilla Firefox Mobile, contains a vulnerability that can be exploited by remote attackers. This flaw may lead to a denial of service via invalid heap read operations or memory corruption caused by the maliciously crafted TrueType fonts utilizing the MIRP instruction, posing a risk for arbitrary code execution.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.