CVE-2023-2004

Public on 2023-04-14
Modified on 2023-10-17
Description
An integer overflow vulnerability was discovered in Freetype in tt_hvadvance_adjust() function in src/truetype/ttgxvar.c.
Severity
Medium severity
Medium
CVSS v3 Base Score
5.3
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 freetype Not Affected
Amazon Linux 2 - Core freetype Not Affected
Amazon Linux 2023 freetype 2023-05-25 ALAS2023-2023-188 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L