>> FreeType "_bdf_set_default_spacing()" BDF Font Handling Integer Overflow Vulnerability
Title : FreeType "_bdf_set_default_spacing()" BDF Font Handling Integer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2007-1264 CVE ID : CVE-2007-1351
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-04-05
Technical Description
A vulnerability has been identified in FreeType, which could be exploited by attackers to execute arbitrary commands. This issue is caused by an integer overflow error in the "_bdf_set_default_spacing()" [bdf/bdflib.c] function when processing malformed BDF fonts, which could be exploited by attackers to compromise an affected system via a specially crafted file.