First published: Fri Aug 06 2010(Updated: )
A stack-based buffer overflow was found in the way FreeType font rendering engine processed certain Adobe Type 1 Mac Font File (LWFN) fonts. An attacker could use this flaw to create a specially-crafted font file that, when opened, would cause an application linked against libfreetype to crash, or, possibly execute arbitrary code. Upstream bug report: [1] <a href="https://savannah.nongnu.org/bugs/?30658">https://savannah.nongnu.org/bugs/?30658</a> Public reproducer: [2] <a href="http://alt.swiecki.net/j/f/sigsegv31.ttf">http://alt.swiecki.net/j/f/sigsegv31.ttf</a> Upstream changeset: [3] <a href="http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=81f3472c0ba7b8f6466e2e214fa8c1c17fade975">http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=81f3472c0ba7b8f6466e2e214fa8c1c17fade975</a> Credit: Robert Swiecki
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
FreeType | <2.4.2 | |
Apple Mac OS X | <10.6.5 | |
Apple iPhone OS | <4.2 | |
Apple tvOS | <4.1.0 | |
Canonical Ubuntu Linux | =9.04 | |
Canonical Ubuntu Linux | =8.04 | |
Canonical Ubuntu Linux | =9.10 | |
Canonical Ubuntu Linux | =10.04 | |
Canonical Ubuntu Linux | =6.06 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.