Security Bulletin: IBM Cognos Transformer has addressed a vulnerability in FreeType (CVE-2025-27363)

Vulnerability Details

Basic Information

Title Security Bulletin: IBM Cognos Transformer has addressed a vulnerability in FreeType (CVE-2025-27363)
Type ibm
Published 2025-04-29T16:11:17
Last Seen 2025-04-29T18:56:36
CVSS Score 8.1 (HIGH)

CVSS v3 Details

Attack Vector NETWORK
Attack Complexity HIGH
Privileges Required NONE
User Interaction NONE
Scope UNCHANGED
Confidentiality Impact HIGH
Integrity Impact HIGH
Availability Impact HIGH

CVE Information

CVE IDs CVE-2025-27363
CWE
Bulletin Family software

Description

## Summary

IBM Cognos Transformer is considered affected by an arbitrary code execution in FreeType (CVE-2025-27363).

## Vulnerability Details

**CVEID:**CVE-2025-27363
**DESCRIPTION:** An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.
**CWE:**CWE-787: Out-of-bounds Write
**CVSS Source:** [email protected]
**CVSS Base score:** 8.1
**CVSS Vector:**(CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

## Affected Products and Versions

Affected Product(s)| Version(s)
—|—
IBM Cognos Transformer| 12.1.0
IBM Cognos Transformer| 12.0.0-12.0.4
IBM Cognos Transformer| 11.2.0-11.2.4 FP5

## Remediation/Fixes

Affected Product(s)| Version(s)| Remediation/Fix/Instructions
—|—|—
IBM Cognos Transformer| 12.1.0| IBM Cognos Analytics 12.1.0 iF1
IBM Cognos Transformer| 12.0.0-12.0.4| IBM Cognos Analytics 12.0.4 IF3
IBM Cognos Transformer| 11.2.0-11.2.4 FP5| IBM Cognos Analytics 11.2.4 IF5

## Workarounds and Mitigations

None

##

Impact Assessment

Base Score 8.1
Severity HIGH

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.