CVE-2015-3905
published 2015-06-08CVE-2015-3905: Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.39 allows remote attackers to cause a denial of service (crash) and possibly…
PriorityP339high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
6.91%
93.4th percentile
Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.39 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | t1utils | < t1utils 1.38-4 (bookworm) | t1utils 1.38-4 (bookworm) |
| t1utils_project | t1utils | — | — |
| t1utils_project | t1utils | >= 0 < 1.38-4 | 1.38-4 |
| t1utils_project | t1utils | >= 0 < 1.38-4 | 1.38-4 |
| t1utils_project | t1utils | >= 0 < 1.38-4 | 1.38-4 |
| t1utils_project | t1utils | >= 0 < 1.38-4 | 1.38-4 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco SIP Phone 3905 Resource Limitation Denial of Service Vulnerability
vendor_cisco·2015-12-02·CVSS 5.0
CVE-2015-6391 [MEDIUM] CWE-119 Cisco SIP Phone 3905 Resource Limitation Denial of Service Vulnerability
Cisco SIP Phone 3905 Resource Limitation Denial of Service Vulnerability
A vulnerability in the Cisco Unified SIP Phone 3905 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
The vulnerability is due to a resource limitation of the device. An attacker could exploit this vulnerability by sending large amounts of traffic to the affected device. An exploit could cause the device to stop functioning properly, resulting in a DOS condition.
Cisco has not released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151202-sip
Ubuntu
t1utils vulnerability
vendor_ubuntu·2015-06-03
CVE-2015-3905 t1utils vulnerability
Title: t1utils vulnerability
Summary: t1utils could be made to crash or run programs as your login if it
opened a specially crafted file.
Jakub Wilk discovered that t1utils incorrectly handled certain malformed fonts.
If a user or automated system were tricked into opening a specially crafted
font, a remote attacker could crash the application, leading to a denial of
service, or possibly execute arbitrary code with user privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
t1utils: buffer overflow flaw
vendor_redhat·2015-02-26·CVSS 7.5
CVE-2015-3905 [HIGH] CWE-120 t1utils: buffer overflow flaw
t1utils: buffer overflow flaw
Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.39 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
A buffer overflow flaw was found in the way t1utils processed, for example, certain PFB (Printer Font Binary) files. An attacker could use this flaw to potentially execute arbitrary code by tricking a user into processing a specially crafted PFB file with t1utils.
Package: t1utils (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2015-3905: t1utils - Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.3...
vendor_debian·2015·CVSS 7.5
CVE-2015-3905 [HIGH] CVE-2015-3905: t1utils - Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.3...
Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.39 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
Scope: local
bookworm: resolved (fixed in 1.38-4)
bullseye: resolved (fixed in 1.38-4)
forky: resolved (fixed in 1.38-4)
sid: resolved (fixed in 1.38-4)
trixie: resolved (fixed in 1.38-4)
Cisco
Cisco SIP Phone 3905 Resource Limitation Denial of Service Vulnerability
vendor_cisco
CVE-2015-6391 Cisco SIP Phone 3905 Resource Limitation Denial of Service Vulnerability
CVE-2015-6391: Cisco SIP Phone 3905 Resource Limitation Denial of Service Vulnerability
A vulnerability in the Cisco Unified SIP Phone 3905 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a resource limitation of the device. An attacker could exploit this vulnerability by sending large amounts of traffic to the affected device. An exploit could cause the device to stop functioning properly, resulting in a DOS condition. Cisco has not released software updates that address this vulnerability. There are no
CWE: CWE-119, CWE-119
Bug IDs: CSCuh51331
GHSA
GHSA-8h55-h9jf-42p4: Buffer overflow in the set_cs_start function in t1disasm
ghsa_unreviewed·2022-05-17
CVE-2015-3905 [HIGH] CWE-119 GHSA-8h55-h9jf-42p4: Buffer overflow in the set_cs_start function in t1disasm
Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.39 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
OSV
CVE-2015-3905: Buffer overflow in the set_cs_start function in t1disasm
osv·2015-06-08·CVSS 7.5
CVE-2015-3905 [HIGH] CVE-2015-3905: Buffer overflow in the set_cs_start function in t1disasm
Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.39 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
No detection rules found.
No public exploits indexed.
http://ubuntu.com/usn/usn-2627-1http://www.openwall.com/lists/oss-security/2015/05/13/9http://www.openwall.com/lists/oss-security/2015/05/22/10http://www.securityfocus.com/bid/74674https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=779274https://bugzilla.redhat.com/show_bug.cgi?id=1218365https://github.com/kohler/t1utils/blob/master/NEWShttps://github.com/kohler/t1utils/commit/6b9d1aafcb61a3663c883663eb19ccdbfcde8d33https://github.com/kohler/t1utils/issues/4https://security.gentoo.org/glsa/201507-10http://ubuntu.com/usn/usn-2627-1http://www.openwall.com/lists/oss-security/2015/05/13/9http://www.openwall.com/lists/oss-security/2015/05/22/10http://www.securityfocus.com/bid/74674https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=779274https://bugzilla.redhat.com/show_bug.cgi?id=1218365https://github.com/kohler/t1utils/blob/master/NEWShttps://github.com/kohler/t1utils/commit/6b9d1aafcb61a3663c883663eb19ccdbfcde8d33https://github.com/kohler/t1utils/issues/4https://security.gentoo.org/glsa/201507-10
2015-06-08
Published