PT-2012-6348 · Freetype+3 · Libfreetype6-Debuginfo-X86+13
Mateusz Jurczyk
·
Published
1970-01-01
·
Updated
2024-06-15
·
CVE-2012-1137
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
freetype versions prior to 2.4.9
libfreetype6 versions prior to 2.4.9
libfreetype6-32bit versions prior to 2.4.9
libfreetype6-debuginfo versions prior to 2.4.9
libfreetype6-debuginfo-32bit versions prior to 2.4.9
libfreetype6-debuginfo-x86 versions prior to 2.4.9
libfreetype6-x86 versions prior to 2.4.9
freetype2-devel versions prior to 2.4.9
freetype2-devel-32bit versions prior to 2.4.9
ft2demos versions prior to 2.4.9
freetype2-debugsource versions prior to 2.4.9
Description
The issue is related to multiple vulnerabilities in the freetype package, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely, potentially causing a denial of service or allowing the execution of arbitrary code via a crafted header in a BDF font.
Recommendations
For freetype versions prior to 2.4.9, update to version 2.4.9 or later.
For libfreetype6 versions prior to 2.4.9, update to version 2.4.9 or later.
For libfreetype6-32bit versions prior to 2.4.9, update to version 2.4.9 or later.
For libfreetype6-debuginfo versions prior to 2.4.9, update to version 2.4.9 or later.
For libfreetype6-debuginfo-32bit versions prior to 2.4.9, update to version 2.4.9 or later.
For libfreetype6-debuginfo-x86 versions prior to 2.4.9, update to version 2.4.9 or later.
For libfreetype6-x86 versions prior to 2.4.9, update to version 2.4.9 or later.
For freetype2-devel versions prior to 2.4.9, update to version 2.4.9 or later.
For freetype2-devel-32bit versions prior to 2.4.9, update to version 2.4.9 or later.
For ft2demos versions prior to 2.4.9, update to version 2.4.9 or later.
For freetype2-debugsource versions prior to 2.4.9, update to version 2.4.9 or later.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Red Hat
Suse
Freetype
Freetype2-Debugsource
Freetype2-Devel
Freetype2-Devel-32Bit
Ft2Demos
Libfreetype6
Libfreetype6-32Bit
Libfreetype6-Debuginfo
Libfreetype6-Debuginfo-32Bit
Libfreetype6-Debuginfo-X86
Libfreetype6-X86