CVE-2012-1139
published 2012-04-25CVE-2012-1139: Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of…
PriorityP340critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.81%
88.9th percentile
Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid stack read operation and memory corruption) or possibly execute arbitrary code via crafted glyph data in a BDF font.
Affected
62 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freetype | < freetype 2.4.9-1 (bookworm) | freetype 2.4.9-1 (bookworm) |
| freetype | freetype | <= 2.4.8 | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_ubuntu10.0CRITICAL
vendor_debian9.3LOW
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c8fh-cq7g-679p: Array index error in FreeType before 2
ghsa_unreviewed·2022-05-13
CVE-2012-1139 [HIGH] CWE-119 GHSA-c8fh-cq7g-679p: Array index error in FreeType before 2
Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid stack read operation and memory corruption) or possibly execute arbitrary code via crafted glyph data in a BDF font.
OSV
CVE-2012-1139: Array index error in FreeType before 2
osv·2012-04-25·CVSS 9.3
CVE-2012-1139 [CRITICAL] CVE-2012-1139: Array index error in FreeType before 2
Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid stack read operation and memory corruption) or possibly execute arbitrary code via crafted glyph data in a BDF font.
Ubuntu
FreeType vulnerabilities
vendor_ubuntu·2012-03-23·CVSS 10.0
CVE-2012-1126 [CRITICAL] FreeType vulnerabilities
Title: FreeType vulnerabilities
Summary: FreeType could be made to crash or run programs as your login if it opened a
specially crafted font file.
Mateusz Jurczyk discovered that FreeType did not correctly handle certain
malformed BDF font files. If a user were tricked into using a specially crafted
font file, a remote attacker could cause FreeType to crash. (CVE-2012-1126)
Mateusz Jurczyk discovered that FreeType did not correctly handle certain
malformed BDF font files. If a user were tricked into using a specially crafted
font file, a remote attacker could cause FreeType to crash. (CVE-2012-1127)
Mateusz Jurczyk discovered that FreeType did not correctly handle certain
malformed TrueType font files. If a user were tricked into using a specially
crafted font file, a remote attacker c
Red Hat
freetype: data buffer underflow in BDF parser _bdf_parse_glyphs() (#35656)
vendor_redhat·2012-02-28·CVSS 9.3
CVE-2012-1139 [CRITICAL] CWE-121 freetype: data buffer underflow in BDF parser _bdf_parse_glyphs() (#35656)
freetype: data buffer underflow in BDF parser _bdf_parse_glyphs() (#35656)
Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid stack read operation and memory corruption) or possibly execute arbitrary code via crafted glyph data in a BDF font.
Debian
CVE-2012-1139: freetype - Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile be...
vendor_debian·2012·CVSS 9.3
CVE-2012-1139 [CRITICAL] CVE-2012-1139: freetype - Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile be...
Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid stack read operation and memory corruption) or possibly execute arbitrary code via crafted glyph data in a BDF font.
Scope: local
bookworm: resolved (fixed in 2.4.9-1)
bullseye: resolved (fixed in 2.4.9-1)
forky: resolved (fixed in 2.4.9-1)
sid: resolved (fixed in 2.4.9-1)
trixie: resolved (fixed in 2.4.9-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-{1126,1127,1128,1130,1131,1132,1133,1134,1135,1136,1137,1138,1139,1140,1141,1142,1143,1144} freetype: multiple vulnerabilities [fedora-all]
bugzilla·2012-03-23
[HIGH] CVE-2012-{1126,1127,1128,1130,1131,1132,1133,1134,1135,1136,1137,1138,1139,1140,1141,1142,1143,1144} freetype: multiple vulnerabilities [fedora-all]
CVE-2012-{1126,1127,1128,1130,1131,1132,1133,1134,1135,1136,1137,1138,1139,1140,1141,1142,1143,1144} freetype: multiple vulnerabilities [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update sub
Bugzilla
CVE-2012-1139 freetype: data buffer underflow in BDF parser _bdf_parse_glyphs() (#35656)
bugzilla·2012-03-06·CVSS 9.3
CVE-2012-1139 [CRITICAL] CVE-2012-1139 freetype: data buffer underflow in BDF parser _bdf_parse_glyphs() (#35656)
CVE-2012-1139 freetype: data buffer underflow in BDF parser _bdf_parse_glyphs() (#35656)
An array index error, leading to out-of stack-based buffer read flaw was found in the way FreeType font rendering engine processed certain glyph information for glyph bitmap distribution format (BDF) font files. A remote attacker could provide a specially-crafted BDF font file, which once opened in an application linked against FreeType would lead to that application crash.
Upstream bug report:
[1] https://savannah.nongnu.org/bugs/?35656
Upstream patch:
[2] http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=6ac022dc750d95296a6f731b9594f2e751d997fa
Acknowledgements:
Red Hat would like to thank Mateusz Jurczyk of the Google Security Team for reporting this issue.
Discussion:
Added
http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0467.htmlhttp://secunia.com/advisories/48508http://secunia.com/advisories/48758http://secunia.com/advisories/48797http://secunia.com/advisories/48822http://secunia.com/advisories/48918http://secunia.com/advisories/48951http://secunia.com/advisories/48973http://security.gentoo.org/glsa/glsa-201204-04.xmlhttp://support.apple.com/kb/HT5503http://www.mandriva.com/security/advisories?name=MDVSA-2012:057http://www.mozilla.org/security/announce/2012/mfsa2012-21.htmlhttp://www.openwall.com/lists/oss-security/2012/03/06/16http://www.securityfocus.com/bid/52318http://www.securitytracker.com/id?1026765http://www.ubuntu.com/usn/USN-1403-1https://bugzilla.mozilla.org/show_bug.cgi?id=733512https://bugzilla.redhat.com/show_bug.cgi?id=800598http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0467.htmlhttp://secunia.com/advisories/48508http://secunia.com/advisories/48758http://secunia.com/advisories/48797http://secunia.com/advisories/48822http://secunia.com/advisories/48918http://secunia.com/advisories/48951http://secunia.com/advisories/48973http://security.gentoo.org/glsa/glsa-201204-04.xmlhttp://support.apple.com/kb/HT5503http://www.mandriva.com/security/advisories?name=MDVSA-2012:057http://www.mozilla.org/security/announce/2012/mfsa2012-21.htmlhttp://www.openwall.com/lists/oss-security/2012/03/06/16http://www.securityfocus.com/bid/52318http://www.securitytracker.com/id?1026765http://www.ubuntu.com/usn/USN-1403-1https://bugzilla.mozilla.org/show_bug.cgi?id=733512https://bugzilla.redhat.com/show_bug.cgi?id=800598
2012-04-25
Published