CVE-2015-9290: Critical severity freetype vulnerability
Published Jul 30, 2019
·Updated
In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1GetPrivateDict where there is no check that the new values of cur and limit are sensible before going to Again.
Affected Software
1 affected component
FreeType<2.6.1
Remediation
Event History
Jul 30, 2019
CVE Published
via MITRE·12:36 PM
Data Sourced
via MITRE·12:36 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2015-9290.
2
What is the severity of CVE-2015-9290?
The severity of CVE-2015-9290 is critical, with a severity value of 9.8.
3
What is the description of CVE-2015-9290?
CVE-2015-9290 is a buffer over-read vulnerability in FreeType before 2.6.1, specifically in the type1/t1parse.c file.
4
What software is affected by CVE-2015-9290?
The affected software is FreeType before version 2.6.1.
5
How do I fix CVE-2015-9290?
To fix CVE-2015-9290, it is recommended to update FreeType to version 2.6.1 or later.