|
|
Subscribe / Log in / New account

freetype2: multiple vulnerabilities

Package(s):freetype2 CVE #(s):CVE-2012-5668 CVE-2012-5669 CVE-2012-5670
Created:December 28, 2012 Updated:March 18, 2015
Description:

From the Mageia advisory:

A null pointer de-reference flaw was found in the way Freetype font rendering engine handled Glyph bitmap distribution format (BDF) fonts. A remote attacker could provide a specially-crafted BDF font file, which once processed in an application linked against FreeType would lead to that application crash (CVE-2012-5668).

An out-of heap-based buffer read flaw was found in the way FreeType font rendering engine performed parsing of glyph information and relevant bitmaps for glyph bitmap distribution format (BDF). A remote attacker could provide a specially-crafted BDF font file, which once opened in an application linked against FreeType would lead to that application crash (CVE-2012-5669).

An out-of heap-based buffer write flaw was found in the way FreeType font rendering engine performed parsing of glyph information and relevant bitmaps for glyph bitmap distribution format (BDF). A remote attacker could provide a specially-crafted font file, which once opened in an application linked against FreeType would lead to that application crash, or, potentially, arbitrary code execution with the privileges of the user running the application (CVE-2012-5670).

Alerts:
Oracle ELSA-2015-0696 freetype 2015-03-17
Gentoo 201402-16 freetype 2014-02-11
Mandriva MDVSA-2013:039 freetype2 2013-04-05
Fedora FEDORA-2013-1466 freetype 2013-02-12
Fedora FEDORA-2013-1492 freetype 2013-02-05
Scientific Linux SL-free-20130201 freetype 2013-02-01
Oracle ELSA-2013-0216 freetype 2013-02-01
Oracle ELSA-2013-0216 freetype 2013-02-01
Mandriva MDVSA-2013:006 freetype2 2013-02-01
CentOS CESA-2013:0216 freetype 2013-02-01
CentOS CESA-2013:0216 freetype 2013-01-31
Red Hat RHSA-2013:0216-01 freetype 2013-01-31
openSUSE openSUSE-SU-2013:0189-1 update 2013-01-23
openSUSE openSUSE-SU-2013:0177-1 freetype2 2013-01-23
openSUSE openSUSE-SU-2013:0165-1 freetype2 2013-01-23
Slackware SSA:2013-015-01 freetype 2013-01-15
Ubuntu USN-1686-1 freetype 2013-01-14
Mageia MGASA-2012-0369 freetype2 2012-12-27

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds