CVE-2015-9383: Medium severity freetype vulnerability
FreeType before 2.6.2 has a heap-based buffer over-read in ttcmap14validate in sfnt/ttcmap.c.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2015-9383?
CVE-2015-9383 is a vulnerability in FreeType before 2.6.2 that allows for a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.
How severe is CVE-2015-9383?
CVE-2015-9383 has a severity rating of 6.5 (Medium).
Which software is affected by CVE-2015-9383?
FreeType versions before 2.6.2 are affected, including certain versions of Debian and Ubuntu Linux.
How can I fix the CVE-2015-9383 vulnerability in FreeType?
To fix the CVE-2015-9383 vulnerability in FreeType, update to version 2.9.1-3+deb10u3 (or higher) on Debian, or version 2.5.2-1ubuntu2.8+ (or higher) on Ubuntu.
Where can I find more information about CVE-2015-9383?
You can find more information about CVE-2015-9383 in the references provided: [link1](http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=57cbb8c148999ba8f14ed53435fc071ac9953afd), [link2](https://lists.debian.org/debian-lts-announce/2019/09/msg00002.html), [link3](https://savannah.nongnu.org/bugs/?46346).