CVE-2022-27404

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-27404
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-27404.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-27404
Related
Published
2022-04-22T14:15:09Z
Modified
2024-09-18T03:17:46.112068Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfntinitface.

References

Affected packages

Alpine:v3.12 / freetype

Package

Name
freetype
Purl
pkg:apk/alpine/freetype?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.10.4-r1

Affected versions

2.*

2.3.8-r0
2.3.8-r1
2.3.12-r0
2.4.0-r0
2.4.1-r0
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.4-r2
2.4.4-r3
2.4.5-r0
2.4.5-r1
2.4.6-r0
2.4.7-r0
2.4.8-r0
2.4.9-r0
2.4.10-r0
2.4.11-r0
2.4.12-r0
2.5.0.1-r0
2.5.0.1-r1
2.5.1-r0
2.5.1-r1
2.5.1-r2
2.5.2-r0
2.5.2-r1
2.5.3-r0
2.5.4-r0
2.5.5-r0
2.6-r0
2.6-r1
2.6-r2
2.6-r3
2.6-r4
2.6.2-r0
2.6.3-r0
2.7-r0
2.7.1-r0
2.7.1-r1
2.8-r0
2.8-r1
2.8-r2
2.8-r3
2.8.1-r0
2.8.1-r1
2.8.1-r2
2.8.1-r3
2.9-r0
2.9-r1
2.9.1-r0
2.9.1-r1
2.9.1-r2
2.10.0-r0
2.10.1-r0
2.10.2-r0
2.10.4-r0

Alpine:v3.13 / freetype

Package

Name
freetype
Purl
pkg:apk/alpine/freetype?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.10.4-r2

Affected versions

2.*

2.3.8-r0
2.3.8-r1
2.3.12-r0
2.4.0-r0
2.4.1-r0
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.4-r2
2.4.4-r3
2.4.5-r0
2.4.5-r1
2.4.6-r0
2.4.7-r0
2.4.8-r0
2.4.9-r0
2.4.10-r0
2.4.11-r0
2.4.12-r0
2.5.0.1-r0
2.5.0.1-r1
2.5.1-r0
2.5.1-r1
2.5.1-r2
2.5.2-r0
2.5.2-r1
2.5.3-r0
2.5.4-r0
2.5.5-r0
2.6-r0
2.6-r1
2.6-r2
2.6-r3
2.6-r4
2.6.2-r0
2.6.3-r0
2.7-r0
2.7.1-r0
2.7.1-r1
2.8-r0
2.8-r1
2.8-r2
2.8-r3
2.8.1-r0
2.8.1-r1
2.8.1-r2
2.8.1-r3
2.9-r0
2.9-r1
2.9.1-r0
2.9.1-r1
2.9.1-r2
2.10.0-r0
2.10.1-r0
2.10.2-r0
2.10.3-r0
2.10.4-r0
2.10.4-r1

Alpine:v3.14 / freetype

Package

Name
freetype
Purl
pkg:apk/alpine/freetype?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.10.4-r2

Affected versions

2.*

2.3.8-r0
2.3.8-r1
2.3.12-r0
2.4.0-r0
2.4.1-r0
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.4-r2
2.4.4-r3
2.4.5-r0
2.4.5-r1
2.4.6-r0
2.4.7-r0
2.4.8-r0
2.4.9-r0
2.4.10-r0
2.4.11-r0
2.4.12-r0
2.5.0.1-r0
2.5.0.1-r1
2.5.1-r0
2.5.1-r1
2.5.1-r2
2.5.2-r0
2.5.2-r1
2.5.3-r0
2.5.4-r0
2.5.5-r0
2.6-r0
2.6-r1
2.6-r2
2.6-r3
2.6-r4
2.6.2-r0
2.6.3-r0
2.7-r0
2.7.1-r0
2.7.1-r1
2.8-r0
2.8-r1
2.8-r2
2.8-r3
2.8.1-r0
2.8.1-r1
2.8.1-r2
2.8.1-r3
2.9-r0
2.9-r1
2.9.1-r0
2.9.1-r1
2.9.1-r2
2.10.0-r0
2.10.1-r0
2.10.2-r0
2.10.3-r0
2.10.4-r0
2.10.4-r1

Alpine:v3.15 / freetype

Package

Name
freetype
Purl
pkg:apk/alpine/freetype?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.11.1-r1

Affected versions

2.*

2.3.8-r0
2.3.8-r1
2.3.12-r0
2.4.0-r0
2.4.1-r0
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.4-r2
2.4.4-r3
2.4.5-r0
2.4.5-r1
2.4.6-r0
2.4.7-r0
2.4.8-r0
2.4.9-r0
2.4.10-r0
2.4.11-r0
2.4.12-r0
2.5.0.1-r0
2.5.0.1-r1
2.5.1-r0
2.5.1-r1
2.5.1-r2
2.5.2-r0
2.5.2-r1
2.5.3-r0
2.5.4-r0
2.5.5-r0
2.6-r0
2.6-r1
2.6-r2
2.6-r3
2.6-r4
2.6.2-r0
2.6.3-r0
2.7-r0
2.7.1-r0
2.7.1-r1
2.8-r0
2.8-r1
2.8-r2
2.8-r3
2.8.1-r0
2.8.1-r1
2.8.1-r2
2.8.1-r3
2.9-r0
2.9-r1
2.9.1-r0
2.9.1-r1
2.9.1-r2
2.10.0-r0
2.10.1-r0
2.10.2-r0
2.10.3-r0
2.10.4-r0
2.10.4-r1
2.11.0-r0
2.11.1-r0

Alpine:v3.16 / freetype

Package

Name
freetype
Purl
pkg:apk/alpine/freetype?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.12.1-r0

Affected versions

2.*

2.3.8-r0
2.3.8-r1
2.3.12-r0
2.4.0-r0
2.4.1-r0
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.4-r2
2.4.4-r3
2.4.5-r0
2.4.5-r1
2.4.6-r0
2.4.7-r0
2.4.8-r0
2.4.9-r0
2.4.10-r0
2.4.11-r0
2.4.12-r0
2.5.0.1-r0
2.5.0.1-r1
2.5.1-r0
2.5.1-r1
2.5.1-r2
2.5.2-r0
2.5.2-r1
2.5.3-r0
2.5.4-r0
2.5.5-r0
2.6-r0
2.6-r1
2.6-r2
2.6-r3
2.6-r4
2.6.2-r0
2.6.3-r0
2.7-r0
2.7.1-r0
2.7.1-r1
2.8-r0
2.8-r1
2.8-r2
2.8-r3
2.8.1-r0
2.8.1-r1
2.8.1-r2
2.8.1-r3
2.9-r0
2.9-r1
2.9.1-r0
2.9.1-r1
2.9.1-r2
2.10.0-r0
2.10.1-r0
2.10.2-r0
2.10.3-r0
2.10.4-r0
2.10.4-r1
2.11.0-r0
2.11.1-r0
2.11.1-r1

Alpine:v3.17 / freetype

Package

Name
freetype
Purl
pkg:apk/alpine/freetype?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.12.1-r0

Affected versions

2.*

2.3.8-r0
2.3.8-r1
2.3.12-r0
2.4.0-r0
2.4.1-r0
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.4-r2
2.4.4-r3
2.4.5-r0
2.4.5-r1
2.4.6-r0
2.4.7-r0
2.4.8-r0
2.4.9-r0
2.4.10-r0
2.4.11-r0
2.4.12-r0
2.5.0.1-r0
2.5.0.1-r1
2.5.1-r0
2.5.1-r1
2.5.1-r2
2.5.2-r0
2.5.2-r1
2.5.3-r0
2.5.4-r0
2.5.5-r0
2.6-r0
2.6-r1
2.6-r2
2.6-r3
2.6-r4
2.6.2-r0
2.6.3-r0
2.7-r0
2.7.1-r0
2.7.1-r1
2.8-r0
2.8-r1
2.8-r2
2.8-r3
2.8.1-r0
2.8.1-r1
2.8.1-r2
2.8.1-r3
2.9-r0
2.9-r1
2.9.1-r0
2.9.1-r1
2.9.1-r2
2.10.0-r0
2.10.1-r0
2.10.2-r0
2.10.3-r0
2.10.4-r0
2.10.4-r1
2.11.0-r0
2.11.1-r0
2.11.1-r1

Alpine:v3.18 / freetype

Package

Name
freetype
Purl
pkg:apk/alpine/freetype?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.12.1-r0

Affected versions

2.*

2.3.8-r0
2.3.8-r1
2.3.12-r0
2.4.0-r0
2.4.1-r0
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.4-r2
2.4.4-r3
2.4.5-r0
2.4.5-r1
2.4.6-r0
2.4.7-r0
2.4.8-r0
2.4.9-r0
2.4.10-r0
2.4.11-r0
2.4.12-r0
2.5.0.1-r0
2.5.0.1-r1
2.5.1-r0
2.5.1-r1
2.5.1-r2
2.5.2-r0
2.5.2-r1
2.5.3-r0
2.5.4-r0
2.5.5-r0
2.6-r0
2.6-r1
2.6-r2
2.6-r3
2.6-r4
2.6.2-r0
2.6.3-r0
2.7-r0
2.7.1-r0
2.7.1-r1
2.8-r0
2.8-r1
2.8-r2
2.8-r3
2.8.1-r0
2.8.1-r1
2.8.1-r2
2.8.1-r3
2.9-r0
2.9-r1
2.9.1-r0
2.9.1-r1
2.9.1-r2
2.10.0-r0
2.10.1-r0
2.10.2-r0
2.10.3-r0
2.10.4-r0
2.10.4-r1
2.11.0-r0
2.11.1-r0
2.11.1-r1

Alpine:v3.19 / freetype

Package

Name
freetype
Purl
pkg:apk/alpine/freetype?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.12.1-r0

Affected versions

2.*

2.3.8-r0
2.3.8-r1
2.3.12-r0
2.4.0-r0
2.4.1-r0
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.4-r2
2.4.4-r3
2.4.5-r0
2.4.5-r1
2.4.6-r0
2.4.7-r0
2.4.8-r0
2.4.9-r0
2.4.10-r0
2.4.11-r0
2.4.12-r0
2.5.0.1-r0
2.5.0.1-r1
2.5.1-r0
2.5.1-r1
2.5.1-r2
2.5.2-r0
2.5.2-r1
2.5.3-r0
2.5.4-r0
2.5.5-r0
2.6-r0
2.6-r1
2.6-r2
2.6-r3
2.6-r4
2.6.2-r0
2.6.3-r0
2.7-r0
2.7.1-r0
2.7.1-r1
2.8-r0
2.8-r1
2.8-r2
2.8-r3
2.8.1-r0
2.8.1-r1
2.8.1-r2
2.8.1-r3
2.9-r0
2.9-r1
2.9.1-r0
2.9.1-r1
2.9.1-r2
2.10.0-r0
2.10.1-r0
2.10.2-r0
2.10.3-r0
2.10.4-r0
2.10.4-r1
2.11.0-r0
2.11.1-r0
2.11.1-r1

Alpine:v3.20 / freetype

Package

Name
freetype
Purl
pkg:apk/alpine/freetype?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.12.1-r0

Affected versions

2.*

2.3.8-r0
2.3.8-r1
2.3.12-r0
2.4.0-r0
2.4.1-r0
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.4-r2
2.4.4-r3
2.4.5-r0
2.4.5-r1
2.4.6-r0
2.4.7-r0
2.4.8-r0
2.4.9-r0
2.4.10-r0
2.4.11-r0
2.4.12-r0
2.5.0.1-r0
2.5.0.1-r1
2.5.1-r0
2.5.1-r1
2.5.1-r2
2.5.2-r0
2.5.2-r1
2.5.3-r0
2.5.4-r0
2.5.5-r0
2.6-r0
2.6-r1
2.6-r2
2.6-r3
2.6-r4
2.6.2-r0
2.6.3-r0
2.7-r0
2.7.1-r0
2.7.1-r1
2.8-r0
2.8-r1
2.8-r2
2.8-r3
2.8.1-r0
2.8.1-r1
2.8.1-r2
2.8.1-r3
2.9-r0
2.9-r1
2.9.1-r0
2.9.1-r1
2.9.1-r2
2.10.0-r0
2.10.1-r0
2.10.2-r0
2.10.3-r0
2.10.4-r0
2.10.4-r1
2.11.0-r0
2.11.1-r0
2.11.1-r1

Debian:11 / freetype

Package

Name
freetype
Purl
pkg:deb/debian/freetype?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.10.4+dfsg-1+deb11u1

Affected versions

2.*

2.10.4+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / freetype

Package

Name
freetype
Purl
pkg:deb/debian/freetype?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.11.1+dfsg-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / freetype

Package

Name
freetype
Purl
pkg:deb/debian/freetype?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.11.1+dfsg-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/freetype/freetype

Affected ranges

Type
GIT
Repo
https://github.com/freetype/freetype
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

BETA-5
BETA-6
BETA-7
BETA-8
DATE-050920
PRE-2-0-1
PRE-2-0-6
RELEASE-2-0
VER-2-0
VER-2-0-1
VER-2-0-2
VER-2-0-2-TEST
VER-2-0-3
VER-2-0-4
VER-2-0-5
VER-2-0-6
VER-2-0-7
VER-2-0-8
VER-2-1-0
VER-2-1-1
VER-2-1-1-RC1
VER-2-1-10
VER-2-1-2
VER-2-1-2-RC1
VER-2-1-3
VER-2-1-3-RC1
VER-2-1-3-RC2
VER-2-1-3-RC3
VER-2-1-4
VER-2-1-4-RC1
VER-2-1-4-RC2
VER-2-1-5-RC1
VER-2-1-6
VER-2-1-7
VER-2-1-8
VER-2-1-8-RC1
VER-2-1-9
VER-2-10-0
VER-2-10-1
VER-2-10-2
VER-2-10-3
VER-2-10-4
VER-2-11-0
VER-2-11-1
VER-2-2-0
VER-2-2-0-RC1
VER-2-2-0-RC2
VER-2-2-0-RC3
VER-2-2-0-RC4
VER-2-2-1
VER-2-3-0
VER-2-3-0-FINAL
VER-2-3-0-RC1
VER-2-3-0-RC2
VER-2-3-1
VER-2-3-1-FINAL
VER-2-3-10
VER-2-3-11
VER-2-3-12
VER-2-3-2
VER-2-3-3
VER-2-3-4
VER-2-3-5
VER-2-3-5-REAL
VER-2-3-6
VER-2-3-7
VER-2-3-8
VER-2-3-9
VER-2-4-0
VER-2-4-1
VER-2-4-10
VER-2-4-11
VER-2-4-12
VER-2-4-12-beta
VER-2-4-2
VER-2-4-3
VER-2-4-4
VER-2-4-5
VER-2-4-6
VER-2-4-7
VER-2-4-8
VER-2-4-9
VER-2-5-0
VER-2-5-0-1
VER-2-5-1
VER-2-5-2
VER-2-5-3
VER-2-5-4
VER-2-5-5
VER-2-6
VER-2-6-1
VER-2-6-2
VER-2-6-3
VER-2-6-4
VER-2-6-5
VER-2-7
VER-2-7-1
VER-2-8
VER-2-8-1
VER-2-9
VER-2-9-1
VER-2-BETA2
VER-2-BETA3
VER-2-BETA4
freetype
freetype2
import
start