FreeType contains a flaw in src/base/ftcalc.c that may allow a remote denial of service. The issue is triggered when a divide by zero error occurs during font arithmetic computation. With a specially crafted font, a context-dependent attacker can cause a loss of availability for the program.
Classification
Location:
Local / Remote,
Context Dependent
Attack Type:
Denial of Service
Impact:
Loss of Availability
Solution:
Patch / RCS
Exploit:
Exploit Private
Disclosure:
Vendor Verified
Solution
The FreeType Project has released a patch in the GIT repository to address this vulnerability. This patch will be included in version 2.4.9. Check the vendor advisory or solution in the references section.