CVE-2008-1808

Publication date 16 June 2008

Last updated 24 July 2024


Ubuntu priority

Multiple off-by-one errors in FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via (1) a crafted table in a Printer Font Binary (PFB) file or (2) a crafted SHC instruction in a TrueType Font (TTF) file, which triggers a heap-based buffer overflow.

Status

Package Ubuntu Release Status
freetype 8.04 LTS hardy
Fixed 2.3.5-1ubuntu4.8.04.1
7.10 gutsy
Fixed 2.3.5-1ubuntu4.7.10.1
7.04 feisty
Fixed 2.2.1-5ubuntu1.2
6.06 LTS dapper
Fixed 2.1.10-1ubuntu2.5

References

Related Ubuntu Security Notices (USN)

    • USN-643-1
    • FreeType vulnerabilities
    • 11 September 2008

Other references