CVE-2012-5668: FreeType
Medium severity, CVSS 4.3. EPSS: 2.3% chance of exploitation in the next 30 days.
FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to BDF fonts and the improper handling of an "allocation error" in the bdf_free_font function.
Affected products
- FreeType FreeType: up to and including 2.4.10; version 1.3.1 only; version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; …
Published 2013-01-24. Last modified 2026-06-16.