CVE-2023-21261 Information
Jul 14, 2023
cve
Description
In ft_open_face_internal of ftobjs.c there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Reference
https://android.googlesource.com/platform/external/freetype/+/d45f0e49ab54065eb72d92aa3cc5f2152b0910b7 https://source.android.com/security/bulletin/2023-07-01
Share on: