CVE-2012-1137: Buffer Overflow
An out-of heap-based buffer read flaw was found in the way FreeType font rendering engine performed loading and parsing of file header information for glyph bitmap distribution format (BDF) font files. A remote attacker could provide a BDF font file with specially-crafted BDF header, which once processed in an application linked against FreeType would lead to that application crash.
Upstream bug report: [1] https://savannah.nongnu.org/bugs/?35643
Upstream patch: [2] http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=cee5d593582801f65c5e127d9de9ca24ebcdc747
Acknowledgements:
Red Hat would like to thank Mateusz Jurczyk of the Google Security Team for reporting this issue.
Other sources
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted header in a BDF font.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1137?
CVE-2012-1137 is classified as a medium severity vulnerability.
How do I fix CVE-2012-1137?
To fix CVE-2012-1137, upgrade FreeType to version 2.4.9 or later.
What type of vulnerability is CVE-2012-1137?
CVE-2012-1137 is an out-of-bounds read vulnerability affecting the FreeType font rendering engine.
Which versions of FreeType are affected by CVE-2012-1137?
CVE-2012-1137 affects FreeType versions up to and including 2.4.8.
Can CVE-2012-1137 be exploited remotely?
Yes, CVE-2012-1137 can be exploited remotely through specially crafted BDF font files.