CVE-2012-1132
published 2012-04-25CVE-2012-1132: FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap…
PriorityP341critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.81%
88.9th percentile
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted dictionary data in a Type 1 font.
Affected
62 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freetype | < freetype 2.4.9-1 (bookworm) | freetype 2.4.9-1 (bookworm) |
| freetype | freetype | <= 2.4.8 | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_ubuntu10.0CRITICAL
vendor_debian9.3LOW
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5f29-p234-6p39: FreeType before 2
ghsa_unreviewed·2022-05-13
CVE-2012-1132 [HIGH] CWE-119 GHSA-5f29-p234-6p39: FreeType before 2
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted dictionary data in a Type 1 font.
OSV
CVE-2012-1132: FreeType before 2
osv·2012-04-25·CVSS 9.3
CVE-2012-1132 [CRITICAL] CVE-2012-1132: FreeType before 2
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted dictionary data in a Type 1 font.
Red Hat
(64-bit): Multiple integer overflows, leading to DoS or possibly other unspecified impact
vendor_redhat·2012-06-26·CVSS 6.8
CVE-2012-2807 [MEDIUM] CWE-190 (64-bit): Multiple integer overflows, leading to DoS or possibly other unspecified impact
(64-bit): Multiple integer overflows, leading to DoS or possibly other unspecified impact
Multiple integer overflows in libxml2, as used in Google Chrome before 20.0.1132.43 and other products, on 64-bit Linux platforms allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Statement: This issue affected the version of libxml2 as shipped with Red Hat Enterprise Linux 5 and 6 has been addressed via RHSA-2012:1288. This issue does not affect the version of mingw32-libxml2 as shipped with Red Hat Enterprise Linux 6.
Package: mingw32-libxml2 (Red Hat Enterprise Linux 6) - Not affected
Red Hat
libxslt: DoS when reading unexpected DTD nodes in XSLT
vendor_redhat·2012-06-26·CVSS 5.0
CVE-2012-2825 [MEDIUM] libxslt: DoS when reading unexpected DTD nodes in XSLT
libxslt: DoS when reading unexpected DTD nodes in XSLT
The XSL implementation in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service (incorrect read operation) via unspecified vectors.
Package: libxslt (Red Hat Enterprise Linux 4) - Will not fix
Ubuntu
FreeType vulnerabilities
vendor_ubuntu·2012-03-23·CVSS 10.0
CVE-2012-1126 [CRITICAL] FreeType vulnerabilities
Title: FreeType vulnerabilities
Summary: FreeType could be made to crash or run programs as your login if it opened a
specially crafted font file.
Mateusz Jurczyk discovered that FreeType did not correctly handle certain
malformed BDF font files. If a user were tricked into using a specially crafted
font file, a remote attacker could cause FreeType to crash. (CVE-2012-1126)
Mateusz Jurczyk discovered that FreeType did not correctly handle certain
malformed BDF font files. If a user were tricked into using a specially crafted
font file, a remote attacker could cause FreeType to crash. (CVE-2012-1127)
Mateusz Jurczyk discovered that FreeType did not correctly handle certain
malformed TrueType font files. If a user were tricked into using a specially
crafted font file, a remote attacker c
Red Hat
freetype: heap buffer over-read in Type1 parser parse_subrs() (#35606)
vendor_redhat·2012-02-23·CVSS 9.3
CVE-2012-1132 [CRITICAL] CWE-122 freetype: heap buffer over-read in Type1 parser parse_subrs() (#35606)
freetype: heap buffer over-read in Type1 parser parse_subrs() (#35606)
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted dictionary data in a Type 1 font.
Debian
CVE-2012-1132: freetype - FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other...
vendor_debian·2012·CVSS 9.3
CVE-2012-1132 [CRITICAL] CVE-2012-1132: freetype - FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other...
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted dictionary data in a Type 1 font.
Scope: local
bookworm: resolved (fixed in 2.4.9-1)
bullseye: resolved (fixed in 2.4.9-1)
forky: resolved (fixed in 2.4.9-1)
sid: resolved (fixed in 2.4.9-1)
trixie: resolved (fixed in 2.4.9-1)
No detection rules found.
Bugzilla
CVE-2012-{1126,1127,1128,1130,1131,1132,1133,1134,1135,1136,1137,1138,1139,1140,1141,1142,1143,1144} freetype: multiple vulnerabilities [fedora-all]
bugzilla·2012-03-23
[HIGH] CVE-2012-{1126,1127,1128,1130,1131,1132,1133,1134,1135,1136,1137,1138,1139,1140,1141,1142,1143,1144} freetype: multiple vulnerabilities [fedora-all]
CVE-2012-{1126,1127,1128,1130,1131,1132,1133,1134,1135,1136,1137,1138,1139,1140,1141,1142,1143,1144} freetype: multiple vulnerabilities [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update sub
Bugzilla
CVE-2012-1132 freetype: heap buffer over-read in Type1 parser parse_subrs() (#35606)
bugzilla·2012-03-06·CVSS 9.3
CVE-2012-1132 [CRITICAL] CVE-2012-1132 freetype: heap buffer over-read in Type1 parser parse_subrs() (#35606)
CVE-2012-1132 freetype: heap buffer over-read in Type1 parser parse_subrs() (#35606)
An out-of heap-based buffer read flaw was found in the way Type1 font loader of FreeType font rendering engine performed parsing of certain Type1 font dictionary entries. A remote attacker could provide a specially-crafted font file, which once opened in an application linked against FreeType would lead to that application crash.
Upstream bug report:
[1] https://savannah.nongnu.org/bugs/?35606
Upstream patch:
[2] http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=58cbc465d2ccd904dee755cff791fbb3a866646d
Acknowledgements:
Red Hat would like to thank Mateusz Jurczyk of the Google Security Team for reporting this issue.
Discussion:
Added CVE as per http://www.openwall.com/lists/oss-secu
http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0467.htmlhttp://secunia.com/advisories/48508http://secunia.com/advisories/48758http://secunia.com/advisories/48797http://secunia.com/advisories/48822http://secunia.com/advisories/48918http://secunia.com/advisories/48951http://secunia.com/advisories/48973http://security.gentoo.org/glsa/glsa-201204-04.xmlhttp://support.apple.com/kb/HT5503http://www.mandriva.com/security/advisories?name=MDVSA-2012:057http://www.mozilla.org/security/announce/2012/mfsa2012-21.htmlhttp://www.openwall.com/lists/oss-security/2012/03/06/16http://www.securityfocus.com/bid/52318http://www.securitytracker.com/id?1026765http://www.ubuntu.com/usn/USN-1403-1https://bugzilla.mozilla.org/show_bug.cgi?id=733512https://bugzilla.redhat.com/show_bug.cgi?id=800590http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0467.htmlhttp://secunia.com/advisories/48508http://secunia.com/advisories/48758http://secunia.com/advisories/48797http://secunia.com/advisories/48822http://secunia.com/advisories/48918http://secunia.com/advisories/48951http://secunia.com/advisories/48973http://security.gentoo.org/glsa/glsa-201204-04.xmlhttp://support.apple.com/kb/HT5503http://www.mandriva.com/security/advisories?name=MDVSA-2012:057http://www.mozilla.org/security/announce/2012/mfsa2012-21.htmlhttp://www.openwall.com/lists/oss-security/2012/03/06/16http://www.securityfocus.com/bid/52318http://www.securitytracker.com/id?1026765http://www.ubuntu.com/usn/USN-1403-1https://bugzilla.mozilla.org/show_bug.cgi?id=733512https://bugzilla.redhat.com/show_bug.cgi?id=800590
2012-04-25
Published