9.3
CVSSv2

CVE-2011-3439

Published: 11/11/2011 Updated: 22/06/2021
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

FreeType in CoreGraphics in Apple iOS prior to 5.0.1 allows remote malicious users to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a document.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple iphone os

suse linux enterprise desktop 11

suse linux enterprise server 11

suse linux enterprise software development kit 11

Vendor Advisories

Synopsis Important: freetype security update Type/Severity Security Advisory: Important Topic Updated freetype packages that fix multiple security issues are nowavailable for Red Hat Enterprise Linux 56 Extended Update SupportThe Red Hat Security Response Team has rated this update as havingimportant secu ...
Debian Bug report logs - #649122 CVE-2011-3439 Package: freetype; Maintainer for freetype is Hugh McMaster <hughmcmaster@outlookcom>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 17 Nov 2011 21:06:27 UTC Severity: grave Tags: security Fixed in version freetype/248-1 Done: Steve Langasek <vorlo ...
FreeType could be made to crash or run programs as your login if it opened a specially crafted font file ...
Multiple input validation flaws were found in the way FreeType processed CID-keyed fonts If a specially-crafted font file was loaded by an application linked against FreeType, it could cause the application to crash or, potentially, execute arbitrary code with the privileges of the user running the application ...