CVE-2009-0946
published 2009-04-17CVE-2009-0946: Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs…
PriorityP347high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
8.54%
94.5th percentile
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | 1.0.0 – 2.2.1 | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | 10.6.0 – 10.6.4 | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | 10.6.0 – 10.6.4 | — |
| apple | safari | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | freetype | < freetype 2.3.9-4.1 (bookworm) | freetype 2.3.9-4.1 (bookworm) |
| freetype | freetype | <= 2.3.9 | — |
| freetype | freetype | >= 0 < 2.3.9-4.1 | 2.3.9-4.1 |
| freetype | freetype | >= 0 < 2.3.9-4.1 | 2.3.9-4.1 |
| freetype | freetype | >= 0 < 2.3.9-4.1 | 2.3.9-4.1 |
| freetype | freetype | >= 0 < 2.3.9-4.1 | 2.3.9-4.1 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_server | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FreeType vulnerability
vendor_ubuntu·2009-04-27
CVE-2009-0946 FreeType vulnerability
Title: FreeType vulnerability
Summary: FreeType vulnerability
Tavis Ormandy discovered that FreeType did not correctly handle certain
large values in font files. If a user were tricked into using a specially
crafted font file, a remote attacker could execute arbitrary code with user
privileges.
Instructions: After a standard system upgrade you need to restart your session to effect
the necessary changes.
Red Hat
freetype: multiple integer overflows
vendor_redhat·2009-03-20·CVSS 7.5
CVE-2009-0946 [HIGH] CWE-190 freetype: multiple integer overflows
freetype: multiple integer overflows
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
Debian
CVE-2009-0946: freetype - Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers ...
vendor_debian·2009·CVSS 7.5
CVE-2009-0946 [HIGH] CVE-2009-0946: freetype - Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers ...
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
Scope: local
bookworm: resolved (fixed in 2.3.9-4.1)
bullseye: resolved (fixed in 2.3.9-4.1)
forky: resolved (fixed in 2.3.9-4.1)
sid: resolved (fixed in 2.3.9-4.1)
trixie: resolved (fixed in 2.3.9-4.1)
GHSA
GHSA-g82w-w4fh-33xc: Multiple integer overflows in FreeType 2
ghsa_unreviewed·2022-05-02
CVE-2009-0946 [HIGH] CWE-190 GHSA-g82w-w4fh-33xc: Multiple integer overflows in FreeType 2
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
OSV
CVE-2009-0946: Multiple integer overflows in FreeType 2
osv·2009-04-17·CVSS 7.5
CVE-2009-0946 [HIGH] CVE-2009-0946: Multiple integer overflows in FreeType 2
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-0946 freetype: multiple integer overflows
bugzilla·2009-05-26·CVSS 7.5
CVE-2009-0946 [HIGH] CVE-2009-0946 freetype: multiple integer overflows
CVE-2009-0946 freetype: multiple integer overflows
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in all affected branches.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #491384: CVE-2009-0946 freetype: multiple integer overflows
When creating a Bodhi update request, please include the bug IDs of the respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available and only close this bug once all affected Fedora versions are fixed.
Discussion:
As mentioned in the parent bug, not yet fixed in any upstream release. Should affect all current Fedora ver
Bugzilla
CVE-2009-0946 freetype: multiple integer overflows
bugzilla·2009-03-20·CVSS 7.5
CVE-2009-0946 [HIGH] CVE-2009-0946 freetype: multiple integer overflows
CVE-2009-0946 freetype: multiple integer overflows
Created attachment 336091
Tavis' patch for 2.3.8
Discussion:
Created attachment 336092
backported patch to 2.3.5
---
Created attachment 336093
backported patch to 2.2.1
---
Upstream commits to fix this issue:
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=79972af4f0485a11dcb19551356c45245749fc5b
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=a18788b14db60ae3673f932249cd02d33a227c4e
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=0a05ba257b6ddd87dacf8d54b626e4b360e0a596
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=0545ec1ca36b27cb928128870a83e5f668980bc5
---
This issue has been assigned the CVE name CVE-2009-0946
---
Created attachment 339698
upstre
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=0545ec1ca36b27cb928128870a83e5f668980bc5http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=79972af4f0485a11dcb19551356c45245749fc5bhttp://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=a18788b14db60ae3673f932249cd02d33a227c4ehttp://git.savannah.gnu.org/cgit/freetype/freetype2.git/tree/ChangeLoghttp://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2009/jun/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://secunia.com/advisories/34723http://secunia.com/advisories/34913http://secunia.com/advisories/34967http://secunia.com/advisories/35065http://secunia.com/advisories/35074http://secunia.com/advisories/35198http://secunia.com/advisories/35200http://secunia.com/advisories/35204http://secunia.com/advisories/35210http://secunia.com/advisories/35379http://security.gentoo.org/glsa/glsa-200905-05.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-270268-1http://support.apple.com/kb/HT3549http://support.apple.com/kb/HT3613http://support.apple.com/kb/HT3639http://support.apple.com/kb/HT4435http://www.debian.org/security/2009/dsa-1784http://www.mandriva.com/security/advisories?name=MDVSA-2009:243http://www.redhat.com/support/errata/RHSA-2009-0329.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1061.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1062.htmlhttp://www.securityfocus.com/bid/34550http://www.ubuntu.com/usn/USN-767-1http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/1058http://www.vupen.com/english/advisories/2009/1297http://www.vupen.com/english/advisories/2009/1522http://www.vupen.com/english/advisories/2009/1621https://bugzilla.redhat.com/show_bug.cgi?id=491384https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10149http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=0545ec1ca36b27cb928128870a83e5f668980bc5http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=79972af4f0485a11dcb19551356c45245749fc5bhttp://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=a18788b14db60ae3673f932249cd02d33a227c4ehttp://git.savannah.gnu.org/cgit/freetype/freetype2.git/tree/ChangeLoghttp://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2009/jun/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://secunia.com/advisories/34723http://secunia.com/advisories/34913http://secunia.com/advisories/34967http://secunia.com/advisories/35065http://secunia.com/advisories/35074http://secunia.com/advisories/35198http://secunia.com/advisories/35200http://secunia.com/advisories/35204http://secunia.com/advisories/35210http://secunia.com/advisories/35379http://security.gentoo.org/glsa/glsa-200905-05.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-270268-1http://support.apple.com/kb/HT3549http://support.apple.com/kb/HT3613http://support.apple.com/kb/HT3639http://support.apple.com/kb/HT4435http://www.debian.org/security/2009/dsa-1784http://www.mandriva.com/security/advisories?name=MDVSA-2009:243http://www.redhat.com/support/errata/RHSA-2009-0329.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1061.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1062.htmlhttp://www.securityfocus.com/bid/34550http://www.ubuntu.com/usn/USN-767-1http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/1058http://www.vupen.com/english/advisories/2009/1297http://www.vupen.com/english/advisories/2009/1522http://www.vupen.com/english/advisories/2009/1621https://bugzilla.redhat.com/show_bug.cgi?id=491384https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10149
2009-04-17
Published