← Back

CVE-2011-0226

nvd nist
Published: Jul 19, 2011Modified: Apr 29, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Type 1 font in a PDF document, as exploited in the wild in July 2011.

Affected (58)

1 product
Freetype
1 product
Iphone Os
Configuration A
58 vulnerable
Vulnerable SoftwareAffected Versions
Freetype
Up to 2.4.5
Version 2.2.10
Version 2.2.1
Version 2.3.0
Version 2.3.10
Version 2.3.11
Version 2.3.12
Version 2.3.1
Version 2.3.2
Version 2.3.3
Version 2.3.4
Version 2.3.5
Version 2.3.6
Version 2.3.7
Version 2.3.8
Version 2.3.9
Version 2.4.0
Version 2.4.1
Version 2.4.2
Version 2.4.3
Version 2.4.4
Apple
Up to 4.2.8
Version 1.0.0
Version 1.0.1
Version 1.0.2
Version 1.1.0
Version 1.1.1
Version 1.1.2
Version 1.1.3
Version 1.1.4
Version 1.1.5
Version 2.0.0
Version 2.0.1
Version 2.0.2
Version 2.0
Version 2.1.1
Version 2.1
Version 2.2.1
Version 2.2
Version 3.0.1
Version 3.0
Version 3.1.2
Version 3.1.3
Version 3.1
Version 3.2.1
Version 3.2.2
Version 3.2
Version 4.0.1
Version 4.0.2
Version 4.0
Version 4.1
Version 4.2.1
Version 4.2.5
Version 4.2
Version 4.3.0
Version 4.3.1
Version 4.3.2
Version 4.3.3

Related CWEs

References (40)

Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Source: product-security@apple.com
Source: product-security@apple.com
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.