CVE-2011-0226 describes an integer signedness error in the FreeType library, specifically in psaux/t1decode.c, affecting versions prior to 2.4.6. This vulnerability impacts products like Apple iOS (before 4.2.9 and 4.3.x before 4.3.4) and other FreeType integrations. With a CVSS score of 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C), it is a critical vulnerability that can be exploited remotely with medium complexity, potentially leading to arbitrary code execution or denial of service through memory corruption via a crafted Type 1 font embedded in a PDF. This vulnerability was actively exploited in the wild in July 2011, though there is no public exploit code available in Metasploit or ExploitDB, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.4.5CPE matchmatch criteria | cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:* | ||
2.2.1CPE matchmatch criteria | cpe:2.3:a:freetype:freetype:2.2.1:*:*:*:*:*:*:* | ||
2.2.10CPE matchmatch criteria | cpe:2.3:a:freetype:freetype:2.2.10:*:*:*:*:*:*:* | ||
2.3.0CPE matchmatch criteria | cpe:2.3:a:freetype:freetype:2.3.0:*:*:*:*:*:*:* | ||
2.3.1CPE matchmatch criteria | cpe:2.3:a:freetype:freetype:2.3.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.