CVE-2015-9383Out-of-bounds Read in Freetype

CWE-125Out-of-bounds Read10 documents7 sources
Severity
6.5MEDIUMNVD
OSV8.8
EPSS
2.7%
top 14.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 3
Latest updateMay 24

Description

FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

debiandebian/freetype< freetype 2.6.3-1 (bookworm)
NVDfreetype/freetype< 2.6.2
Debianfreetype/freetype< 2.6.3-1+3
Ubuntufreetype/freetype< 2.5.2-1ubuntu2.8+esm1

Also affects: Debian Linux 8.0, Ubuntu Linux 12.04, 14.04, 16.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5qxc-8vc2-mr95: FreeType before 22022-05-24
OSV
freetype vulnerabilities2019-09-09
OSV
CVE-2015-9383: FreeType before 22019-09-03

📋Vendor Advisories

4
Ubuntu
FreeType vulnerability2019-09-09
Ubuntu
FreeType vulnerabilities2019-09-09
Red Hat
freetype: a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c may lead to a DoS2019-09-03
Debian
CVE-2015-9383: freetype - FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in...2015

💬Community

2
Bugzilla
CVE-2015-9383 freetype: a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c may lead to a DoS [fedora-all]2019-10-21
Bugzilla
CVE-2015-9383 freetype: a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c may lead to a DoS2019-10-21