CVE-2016-10244: Debian Linux

High severity, CVSS 7.8. EPSS: 3.4% chance of exploitation in the next 30 days.

The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file.

Affected products

  • Debian Debian Linux: version 8.0 only
  • FreeType FreeType: before 2.7.1 (fixed in 2.7.1)

Published 2017-03-06. Last modified 2026-06-17.