Memory Corruption in FreeType Affects Mozilla Products
CVE-2012-1141

Currently unrated

Key Information:

Vendor

Freetype

Vendor
CVE Published:
25 April 2012

What is CVE-2012-1141?

The FreeType library, utilized in various products including Mozilla Firefox Mobile, is susceptible to a memory corruption vulnerability that can be triggered when a crafted ASCII string in a BDF font is processed. This flaw can lead to unexpected behavior, including a denial-of-service condition due to invalid heap read operations. Attackers can exploit this vulnerability to potentially execute arbitrary code remotely, posing significant risks to users and their devices.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.