CVE-2015-9383
published 2019-09-03CVE-2015-9383: FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.
PriorityP427medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
2.28%
81.2th percentile
FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | freetype | < freetype 2.6.3-1 (bookworm) | freetype 2.6.3-1 (bookworm) |
| freetype | freetype | < 2.6.2 | 2.6.2 |
| freetype | freetype | >= 0 < 2.6.3-1 | 2.6.3-1 |
| freetype | freetype | >= 0 < 2.6.3-1 | 2.6.3-1 |
| freetype | freetype | >= 0 < 2.6.3-1 | 2.6.3-1 |
| freetype | freetype | >= 0 < 2.6.3-1 | 2.6.3-1 |
| freetype | freetype | >= 0 < 2.5.2-1ubuntu2.8+esm1 | 2.5.2-1ubuntu2.8+esm1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FreeType vulnerability
vendor_ubuntu·2019-09-09
CVE-2015-9383 FreeType vulnerability
Title: FreeType vulnerability
Summary: FreeType could be made to expose sensitive information
if it opened a specially crafted font file.
It was discovered that FreeType incorrectly handled certain font files.
An attacker could possibly use this issue to access sensitive information.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Ubuntu
FreeType vulnerabilities
vendor_ubuntu·2019-09-09·CVSS 8.8
CVE-2015-9381 [HIGH] FreeType vulnerabilities
Title: FreeType vulnerabilities
Summary: FreeType could be made to expose sensitive information if it opened a
specially crafted font file.
USN-4126-1 fixed a vulnerability in FreeType. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
It was discovered that FreeType incorrectly handled certain font files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2015-9381, CVE-2015-9382)
Original advisory details:
It was discovered that FreeType incorrectly handled certain font files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2015-9383)
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Red Hat
freetype: a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c may lead to a DoS
vendor_redhat·2019-09-03·CVSS 6.5
CVE-2015-9383 [MEDIUM] CWE-125 freetype: a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c may lead to a DoS
freetype: a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c may lead to a DoS
FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.
Package: freetype (Red Hat Enterprise Linux 5) - Not affected
Package: chromium-browser (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: freetype (Red Hat Enterprise Linux 6) - Will not fix
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: freetype (Red Hat Enterprise Linux 7) - Not affected
Package: freetype (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2015-9383: freetype - FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in...
vendor_debian·2015·CVSS 6.5
CVE-2015-9383 [MEDIUM] CVE-2015-9383: freetype - FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in...
FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.
Scope: local
bookworm: resolved (fixed in 2.6.3-1)
bullseye: resolved (fixed in 2.6.3-1)
forky: resolved (fixed in 2.6.3-1)
sid: resolved (fixed in 2.6.3-1)
trixie: resolved (fixed in 2.6.3-1)
GHSA
GHSA-5qxc-8vc2-mr95: FreeType before 2
ghsa_unreviewed·2022-05-24
CVE-2015-9383 [MEDIUM] CWE-125 GHSA-5qxc-8vc2-mr95: FreeType before 2
FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.
OSV
freetype vulnerabilities
osv·2019-09-09·CVSS 8.8
CVE-2015-9381 [HIGH] freetype vulnerabilities
freetype vulnerabilities
USN-4126-1 fixed a vulnerability in FreeType. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
It was discovered that FreeType incorrectly handled certain font files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2015-9381, CVE-2015-9382)
Original advisory details:
It was discovered that FreeType incorrectly handled certain font files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2015-9383)
OSV
CVE-2015-9383: FreeType before 2
osv·2019-09-03·CVSS 6.5
CVE-2015-9383 [MEDIUM] CVE-2015-9383: FreeType before 2
FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-9383 freetype: a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c may lead to a DoS [fedora-all]
bugzilla·2019-10-21·CVSS 6.5
CVE-2015-9383 [MEDIUM] CVE-2015-9383 freetype: a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c may lead to a DoS [fedora-all]
CVE-2015-9383 freetype: a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c may lead to a DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
Bugzilla
CVE-2015-9383 freetype: a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c may lead to a DoS
bugzilla·2019-10-21·CVSS 6.5
CVE-2015-9383 [MEDIUM] CVE-2015-9383 freetype: a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c may lead to a DoS
CVE-2015-9383 freetype: a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c may lead to a DoS
A heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c may lead to a DoS.
Discussion:
Upstream Issue:
https://savannah.nongnu.org/bugs/?46346
---
Upstream fix:
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=57cbb8c148999ba8f14ed53435fc071ac9953afd
---
Created freetype tracking bugs for this issue:
Affects: fedora-all [bug 1763614]
---
There's a issue with fribidi when handling TrueType fonts using CMAP14 tables. A crafted input can trigger an out of bounds read at tt_cmap14_validate() function due to the lack of validation on the number of table mappings leading to denied of service.
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=57cbb8c148999ba8f14ed53435fc071ac9953afdhttps://lists.debian.org/debian-lts-announce/2019/09/msg00002.htmlhttps://savannah.nongnu.org/bugs/?46346https://usn.ubuntu.com/4126-1/https://usn.ubuntu.com/4126-2/http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=57cbb8c148999ba8f14ed53435fc071ac9953afdhttps://lists.debian.org/debian-lts-announce/2019/09/msg00002.htmlhttps://savannah.nongnu.org/bugs/?46346https://usn.ubuntu.com/4126-1/https://usn.ubuntu.com/4126-2/
2019-09-03
Published