Vulnerability Name: | CVE-2022-27405 (CCN-225145) | ||||||||||||||||||||
Assigned: | 2022-03-19 | ||||||||||||||||||||
Published: | 2022-03-19 | ||||||||||||||||||||
Updated: | 2022-07-27 | ||||||||||||||||||||
Summary: | FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request. | ||||||||||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C)
5.0 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C)
6.4 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H/E:P/RL:O/RC:C)
| ||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||
Vulnerability Type: | CWE-125 CWE-824 | ||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-27405 Source: MISC Type: Not Applicable http://freetype.com Source: XF Type: UNKNOWN freetype-cve202227405-dos(225145) Source: CCN Type: FreeType GitLab src/base/ftobjs.c (FT_Request_Size): Guard `face->size` Source: CCN Type: GitLab Web site SEGV on FT_Set_Char_Size Source: MISC Type: Issue Tracking, Vendor Advisory https://gitlab.freedesktop.org/freetype/freetype/-/issues/1139 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2022-7ece4f6d74 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2022-2dd60f1f00 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2022-80e1724780 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2022-0985b0cb9f Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2022-5e45671294 Source: CCN Type: IBM Security Bulletin 6843911 (App Connect Enterprise Certified Container) IBM App Connect Enterprise Certified Container DesignerAuthoring operands that use mapping assistance may be vulnerable to denial of service due to CVE-2022-27405 Source: CCN Type: IBM Security Bulletin 6852221 (Cloud Transformation Advisor) IBM Cloud Transformation Advisor is vulnerable to multiple vulnerabilities Source: CCN Type: IBM Security Bulletin 6921283 (Robotic Process Automation for Cloud Pak) Multiple Security Vulnerabilities may affect IBM Robotic Process Automation for Cloud Pak. Source: CCN Type: Mend Vulnerability Database CVE-2022-27405 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: Configuration CCN 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |