CVE-2025-23022

FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freetype:freetype:2.8.1:*:*:*:*:*:*:*

History

16 Jan 2025, 21:12

Type Values Removed Values Added
References () https://gitlab.freedesktop.org/freetype/freetype/-/issues/1312 - () https://gitlab.freedesktop.org/freetype/freetype/-/issues/1312 - Exploit
References () https://security-tracker.debian.org/tracker/CVE-2025-23022 - () https://security-tracker.debian.org/tracker/CVE-2025-23022 - Issue Tracking
CPE cpe:2.3:a:freetype:freetype:2.8.1:*:*:*:*:*:*:*
First Time Freetype
Freetype freetype

13 Jan 2025, 21:15

Type Values Removed Values Added
References
  • () https://security-tracker.debian.org/tracker/CVE-2025-23022 -
Summary
  • (es) FreeType 2.8.1 tiene un desbordamiento de entero con signo en cf2_doFlex en cff/cf2intrp.c.

10 Jan 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.0
CWE CWE-190

10 Jan 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-10 15:15

Updated : 2025-01-16 21:12


NVD link : CVE-2025-23022

Mitre link : CVE-2025-23022

CVE.ORG link : CVE-2025-23022


JSON object : View

Products Affected

freetype

  • freetype
CWE
CWE-190

Integer Overflow or Wraparound