CVE-2015-9382
published 2019-09-03CVE-2015-9382: FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face operation.
PriorityP426medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
1.69%
74.5th percentile
FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face operation.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | freetype | < freetype 2.6.1-0.1 (bookworm) | freetype 2.6.1-0.1 (bookworm) |
| freetype | freetype | < 2.6.1 | 2.6.1 |
| freetype | freetype | >= 0 < 2.6.1-0.1 | 2.6.1-0.1 |
| freetype | freetype | >= 0 < 2.6.1-0.1 | 2.6.1-0.1 |
| freetype | freetype | >= 0 < 2.6.1-0.1 | 2.6.1-0.1 |
| freetype | freetype | >= 0 < 2.6.1-0.1 | 2.6.1-0.1 |
| freetype | freetype | >= 0 < 2.5.2-1ubuntu2.8+esm1 | 2.5.2-1ubuntu2.8+esm1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mvvp-jc53-vjxq: FreeType before 2
ghsa_unreviewed·2022-05-24
CVE-2015-9382 [MEDIUM] CWE-125 GHSA-mvvp-jc53-vjxq: FreeType before 2
FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face operation.
OSV
freetype vulnerabilities
osv·2019-09-09·CVSS 8.8
CVE-2015-9381 [HIGH] freetype vulnerabilities
freetype vulnerabilities
USN-4126-1 fixed a vulnerability in FreeType. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
It was discovered that FreeType incorrectly handled certain font files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2015-9381, CVE-2015-9382)
Original advisory details:
It was discovered that FreeType incorrectly handled certain font files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2015-9383)
OSV
CVE-2015-9382: FreeType before 2
osv·2019-09-03·CVSS 6.5
CVE-2015-9382 [MEDIUM] CVE-2015-9382: FreeType before 2
FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face operation.
Ubuntu
FreeType vulnerabilities
vendor_ubuntu·2019-09-09·CVSS 8.8
CVE-2015-9381 [HIGH] FreeType vulnerabilities
Title: FreeType vulnerabilities
Summary: FreeType could be made to expose sensitive information if it opened a
specially crafted font file.
USN-4126-1 fixed a vulnerability in FreeType. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
It was discovered that FreeType incorrectly handled certain font files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2015-9381, CVE-2015-9382)
Original advisory details:
It was discovered that FreeType incorrectly handled certain font files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2015-9383)
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Red Hat
freetype: mishandling ps_parser_skip_PS_token in an FT_New_Memory_Face operation in skip_comment, psaux/psobjs.c, leads to a buffer over-read
vendor_redhat·2019-09-03·CVSS 6.5
CVE-2015-9382 [MEDIUM] CWE-120 freetype: mishandling ps_parser_skip_PS_token in an FT_New_Memory_Face operation in skip_comment, psaux/psobjs.c, leads to a buffer over-read
freetype: mishandling ps_parser_skip_PS_token in an FT_New_Memory_Face operation in skip_comment, psaux/psobjs.c, leads to a buffer over-read
FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face operation.
Package: freetype (Red Hat Enterprise Linux 5) - Out of support scope
Package: chromium-browser (Red Hat Enterprise Linux 6) - Affected
Package: firefox (Red Hat Enterprise Linux 6) - Affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Will not fix
Package: freetype (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2015-9382: freetype - FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c b...
vendor_debian·2015·CVSS 6.5
CVE-2015-9382 [MEDIUM] CVE-2015-9382: freetype - FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c b...
FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face operation.
Scope: local
bookworm: resolved (fixed in 2.6.1-0.1)
bullseye: resolved (fixed in 2.6.1-0.1)
forky: resolved (fixed in 2.6.1-0.1)
sid: resolved (fixed in 2.6.1-0.1)
trixie: resolved (fixed in 2.6.1-0.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-9382 freetype: mishandling ps_parser_skip_PS_token in an FT_New_Memory_Face operation in skip_comment, psaux/psobjs.c, leads to a buffer over-read
bugzilla·2019-10-21·CVSS 6.5
CVE-2015-9382 [MEDIUM] CVE-2015-9382 freetype: mishandling ps_parser_skip_PS_token in an FT_New_Memory_Face operation in skip_comment, psaux/psobjs.c, leads to a buffer over-read
CVE-2015-9382 freetype: mishandling ps_parser_skip_PS_token in an FT_New_Memory_Face operation in skip_comment, psaux/psobjs.c, leads to a buffer over-read
FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face operation. This may lead to a DoS.
Discussion:
Upstream Issue:
https://savannah.nongnu.org/bugs/?45922
---
Upstream fix:
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/src/psaux/psobjs.c?id=db5a4a9ae7b0048f033361744421da8569642f73
---
Created freetype tracking bugs for this issue:
Affects: fedora-all [bug 1763616]
---
The freetype library is able to handle PostScript created fonts, however there's an issue when handling PostScript balanced expressions. On ps_par
Bugzilla
CVE-2015-9382 freetype: mishandling ps_parser_skip_PS_token in an FT_New_Memory_Face operation in skip_comment, psaux/psobjs.c, leads to a buffer over-read [fedora-all]
bugzilla·2019-10-21·CVSS 6.5
CVE-2015-9382 [MEDIUM] CVE-2015-9382 freetype: mishandling ps_parser_skip_PS_token in an FT_New_Memory_Face operation in skip_comment, psaux/psobjs.c, leads to a buffer over-read [fedora-all]
CVE-2015-9382 freetype: mishandling ps_parser_skip_PS_token in an FT_New_Memory_Face operation in skip_comment, psaux/psobjs.c, leads to a buffer over-read [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM cha
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/src/psaux/psobjs.c?id=db5a4a9ae7b0048f033361744421da8569642f73https://access.redhat.com/errata/RHSA-2019:4254https://lists.debian.org/debian-lts-announce/2019/09/msg00002.htmlhttps://savannah.nongnu.org/bugs/?45922https://usn.ubuntu.com/4126-2/http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/src/psaux/psobjs.c?id=db5a4a9ae7b0048f033361744421da8569642f73https://access.redhat.com/errata/RHSA-2019:4254https://lists.debian.org/debian-lts-announce/2019/09/msg00002.htmlhttps://savannah.nongnu.org/bugs/?45922https://usn.ubuntu.com/4126-2/
2019-09-03
Published