CVE-2025-27363
freetype - security update
8.1
HIGH
CVSS 3.1
⚠ KEVEPSS 26.0%
描述
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.
如何修補 CVE-2025-27363
要修補 CVE-2025-27363,請將受影響套件升級到下列已修補版本。
- —升級至 2.13.1-r0 或更新版本
- —升級至 2.10.4+dfsg-1+deb11u2 或更新版本
- —升級至 2.10.4+dfsg-1+deb11u2 或更新版本
- —升級至 2.12.1+dfsg-5+deb12u4 或更新版本
CVE-2025-27363 正在被利用嗎?
是 — CVE-2025-27363 已列入 CISA Known Exploited Vulnerabilities (KEV) 清單,代表正在被實際利用,請立即修補。
受影響套件(4)
- from 0, < 2.13.1-r0
- from 0, < 2.10.4+dfsg-1+deb11u2
- from 0, < 2.10.4+dfsg-1+deb11u2
- from 0, < 2.12.1+dfsg-5+deb12u4
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |