CVE-2018-6942

An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ttinterp.c could lead to DoS via a crafted font file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 41%
Affected Products (NVD)
VendorProductVersion
freetypefreetype
𝑥
≤ 2.9
canonicalubuntu_linux
17.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
freetype
bookworm
2.12.1+dfsg-5+deb12u3
fixed
bullseye
2.10.4+dfsg-1+deb11u1
fixed
jessie
not-affected
sid
2.13.3+dfsg-1
fixed
stretch
not-affected
trixie
2.13.3+dfsg-1
fixed
wheezy
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
freetype
artful
Fixed 2.8-0.2ubuntu2.1
released
trusty
not-affected
xenial
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
freetype2-devel
suse enterprise desktop 15 SP1
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP2
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP3
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP4
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP5
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP6
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP7
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP1
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP2
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP3
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP4
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP5
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP6
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP7
2.10.1-4.3.1
fixed
suse enterprise server 15 SP1
2.10.1-4.3.1
fixed
suse enterprise server 15 SP2
2.10.1-4.3.1
fixed
suse enterprise server 15 SP3
2.10.1-4.3.1
fixed
suse enterprise server 15 SP4
2.10.1-4.3.1
fixed
suse enterprise server 15 SP5
2.10.1-4.3.1
fixed
suse enterprise server 15 SP6
2.10.1-4.3.1
fixed
suse enterprise server 15 SP7
2.10.1-4.3.1
fixed
libfreetype6
suse enterprise desktop 15 SP1
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP2
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP3
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP4
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP5
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP6
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP7
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP1
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP2
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP3
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP4
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP5
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP6
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP7
2.10.1-4.3.1
fixed
suse enterprise server 15 SP1
2.10.1-4.3.1
fixed
suse enterprise server 15 SP2
2.10.1-4.3.1
fixed
suse enterprise server 15 SP3
2.10.1-4.3.1
fixed
suse enterprise server 15 SP4
2.10.1-4.3.1
fixed
suse enterprise server 15 SP5
2.10.1-4.3.1
fixed
suse enterprise server 15 SP6
2.10.1-4.3.1
fixed
suse enterprise server 15 SP7
2.10.1-4.3.1
fixed
libfreetype6-32bit
suse enterprise desktop 15 SP1
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP2
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP3
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP4
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP5
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP6
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP7
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP1
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP2
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP3
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP4
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP5
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP6
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP7
2.10.1-4.3.1
fixed
suse enterprise server 15 SP1
2.10.1-4.3.1
fixed
suse enterprise server 15 SP2
2.10.1-4.3.1
fixed
suse enterprise server 15 SP3
2.10.1-4.3.1
fixed
suse enterprise server 15 SP4
2.10.1-4.3.1
fixed
suse enterprise server 15 SP5
2.10.1-4.3.1
fixed
suse enterprise server 15 SP6
2.10.1-4.3.1
fixed
suse enterprise server 15 SP7
2.10.1-4.3.1
fixed