CVE-2015-9381: High severity freetype vulnerability
Published Sep 3, 2019
·Updated
FreeType before 2.6.1 has a heap-based buffer over-read in T1GetPrivateDict in type1/t1parse.c.
Affected Software
4 affected componentsFixes available
redhat/freetype<2.6.1
2.6.1
debian/freetype
2.10.4+dfsg-1+deb11u12.12.1+dfsg-5+deb12u32.13.3+dfsg-1
FreeType FreeType<2.6.1
Debian Debian Linux=8.0
Remediation
Event History
Sep 3, 2019
CVE Published
via MITRE·04:52 AM
Data Sourced
via MITRE·04:52 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:13 PM
Description
Sep 15, 2024
Data Sourced
via Ubuntu·09:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2015-9381.
2
What is the severity of CVE-2015-9381?
The severity of CVE-2015-9381 is high.
3
Which software versions are affected by CVE-2015-9381?
The affected software versions are FreeType up to version 2.6.1.
4
Is there a fix available for CVE-2015-9381?
Yes, there are fixes available. Please refer to the references for more information.
5
Where can I find more information about CVE-2015-9381?
You can find more information about CVE-2015-9381 in the provided references.