CVE-2015-9381
published 2019-09-03CVE-2015-9381: FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c.
PriorityP337high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.92%
77.6th percentile
FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | freetype | < freetype 2.6.1-0.1 (bookworm) | freetype 2.6.1-0.1 (bookworm) |
| freetype | freetype | < 2.6.1 | 2.6.1 |
| freetype | freetype | >= 0 < 2.6.1-0.1 | 2.6.1-0.1 |
| freetype | freetype | >= 0 < 2.6.1-0.1 | 2.6.1-0.1 |
| freetype | freetype | >= 0 < 2.6.1-0.1 | 2.6.1-0.1 |
| freetype | freetype | >= 0 < 2.6.1-0.1 | 2.6.1-0.1 |
| freetype | freetype | >= 0 < 2.5.2-1ubuntu2.8+esm1 | 2.5.2-1ubuntu2.8+esm1 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jjq3-c7h5-j694: FreeType before 2
ghsa_unreviewed·2022-05-24
CVE-2015-9381 [HIGH] CWE-125 GHSA-jjq3-c7h5-j694: FreeType before 2
FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c.
OSV
freetype vulnerabilities
osv·2019-09-09·CVSS 8.8
CVE-2015-9381 [HIGH] freetype vulnerabilities
freetype vulnerabilities
USN-4126-1 fixed a vulnerability in FreeType. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
It was discovered that FreeType incorrectly handled certain font files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2015-9381, CVE-2015-9382)
Original advisory details:
It was discovered that FreeType incorrectly handled certain font files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2015-9383)
OSV
CVE-2015-9381: FreeType before 2
osv·2019-09-03·CVSS 8.8
CVE-2015-9381 [HIGH] CVE-2015-9381: FreeType before 2
FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c.
Red Hat
freetype: a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c leading to crash
vendor_redhat·2019-09-17·CVSS 8.8
CVE-2015-9381 [HIGH] CWE-125 freetype: a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c leading to crash
freetype: a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c leading to crash
FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c.
An out-of-bounds buffer overflow flaw was found in FreeType prior to version 2.6.1.
Package: freetype (Red Hat Enterprise Linux 5) - Out of support scope
Package: freetype (Red Hat Enterprise Linux 8) - Not affected
Ubuntu
FreeType vulnerabilities
vendor_ubuntu·2019-09-09·CVSS 8.8
CVE-2015-9381 [HIGH] FreeType vulnerabilities
Title: FreeType vulnerabilities
Summary: FreeType could be made to expose sensitive information if it opened a
specially crafted font file.
USN-4126-1 fixed a vulnerability in FreeType. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
It was discovered that FreeType incorrectly handled certain font files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2015-9381, CVE-2015-9382)
Original advisory details:
It was discovered that FreeType incorrectly handled certain font files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2015-9383)
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Debian
CVE-2015-9381: freetype - FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict i...
vendor_debian·2015·CVSS 8.8
CVE-2015-9381 [HIGH] CVE-2015-9381: freetype - FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict i...
FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c.
Scope: local
bookworm: resolved (fixed in 2.6.1-0.1)
bullseye: resolved (fixed in 2.6.1-0.1)
forky: resolved (fixed in 2.6.1-0.1)
sid: resolved (fixed in 2.6.1-0.1)
trixie: resolved (fixed in 2.6.1-0.1)
No detection rules found.
No public exploits indexed.
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/src/type1/t1parse.c?id=7962a15d64c876870ca0ae435ea2467d9be268d9https://access.redhat.com/errata/RHSA-2019:4254https://lists.debian.org/debian-lts-announce/2019/09/msg00002.htmlhttps://savannah.nongnu.org/bugs/?45955https://usn.ubuntu.com/4126-2/http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/src/type1/t1parse.c?id=7962a15d64c876870ca0ae435ea2467d9be268d9https://access.redhat.com/errata/RHSA-2019:4254https://lists.debian.org/debian-lts-announce/2019/09/msg00002.htmlhttps://savannah.nongnu.org/bugs/?45955https://usn.ubuntu.com/4126-2/
2019-09-03
Published