First published: Tue Sep 03 2019(Updated: )
FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Freetype Freetype | <2.6.1 | |
Debian Debian Linux | =8.0 | |
redhat/freetype | <2.6.1 | 2.6.1 |
debian/freetype | 2.10.4+dfsg-1+deb11u1 2.12.1+dfsg-5+deb12u3 2.13.3+dfsg-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2015-9381.
The severity of CVE-2015-9381 is high.
The affected software versions are FreeType up to version 2.6.1.
Yes, there are fixes available. Please refer to the references for more information.
You can find more information about CVE-2015-9381 in the provided references.