CVE-2012-5669: FreeType

Medium severity, CVSS 4.3. EPSS: 3.9% chance of exploitation in the next 30 days.

The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to BDF fonts and an incorrect calculation that triggers an out-of-bounds read.

Affected products

  • FreeType FreeType: up to and including 2.4.10; version 1.3.1 only; version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; …

Published 2013-01-24. Last modified 2026-06-16.