Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Meta Warns of FreeType Vulnerability (CVE-2025-27363) With Active Exploitation Risk

The Hacker News by The Hacker News
March 13, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Mar 13, 2025Ravie LakshmananOpen Source / Vulnerability

Meta has warned that a security vulnerability impacting the FreeType open-source font rendering library may have been exploited in the wild.

The vulnerability has been assigned the CVE identifier CVE-2025-27363, and carries a CVSS score of 8.1, indicating high severity. Described as an out-of-bounds write flaw, it could be exploited to achieve remote code execution when parsing certain font files.

“An out-of-bounds write exists in FreeType versions 2.13.0 and below when attempting to parse font subglyph structures related to TrueType GX and variable font files,” the company said in an advisory.

“The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution.”

Cybersecurity

The company did not share any specifics on how the shortcoming is being exploited, who is behind it, and the scale of the attacks. However, it acknowledged that the bug “may have been exploited in the wild.”

When reached for comment, FreeType developer Werner Lemberg told The Hacker News that a fix for the vulnerability has been incorporated for almost two years. “FreeType versions larger than 2.13.0 are no longer affected,” Lemberg said.

In a separate message posted on the Open Source Security mailing list oss-security, it has come to light that several Linux distributions are running an outdated version of the library, thus rendering them susceptible to the flaw. This includes –

  • AlmaLinux
  • Alpine Linux
  • Amazon Linux 2
  • Debian stable / Devuan
  • RHEL / CentOS Stream / Alma Linux / etc. 8 and 9
  • GNU Guix
  • Mageia
  • OpenMandriva
  • openSUSE Leap
  • Slackware, and
  • Ubuntu 22.04

In light of active exploitation, users are recommended to update their instances to the latest version of FreeType (2.13.3) for optimal protection.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
The Hacker News

The Hacker News

Next Post
VNET Announces Proposed Offering of Convertible Senior Notes

VNET Announces Proposed Offering of Convertible Senior Notes

Recommended.

EU acts to mend ailing AI competitiveness | Computer Weekly

EU acts to mend ailing AI competitiveness | Computer Weekly

May 6, 2025
Midas obtient 80 millions de dollars en série B, soit le plus gros investissement jamais réalisé en Turquie dans le domaine de la fintech

Midas obtient 80 millions de dollars en série B, soit le plus gros investissement jamais réalisé en Turquie dans le domaine de la fintech

August 20, 2025

Trending.

⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More

⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More

October 6, 2025
Cloud Computing on the Rise: Market Projected to Reach .6 Trillion by 2030

Cloud Computing on the Rise: Market Projected to Reach $1.6 Trillion by 2030

August 1, 2025
Stocks making the biggest moves midday: Autodesk, PayPal, Rivian, Nebius, Waters and more

Stocks making the biggest moves midday: Autodesk, PayPal, Rivian, Nebius, Waters and more

July 14, 2025
The Ultimate MSP Guide to Structuring and Selling vCISO Services

The Ultimate MSP Guide to Structuring and Selling vCISO Services

February 19, 2025
Translators’ Voices: China shares technological achievements with the world for mutual benefit

Translators’ Voices: China shares technological achievements with the world for mutual benefit

June 3, 2025

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio