HIGH
freetype: multiple integer overflows
Published Apr 17, 2009
7.5
HIGHCVSS 2.0
EPSS 8.54%
Description
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
Affected products
No data.
Configuration 2
OR
- 4.0
- 5.0
- 6.0
Configuration 3
OR
- 6.06
- 8.04
- 8.10
- 9.04
Configuration 4
OR
- 10.3
- 11.0
- 11.1
- 10
- 11
No data.
Red Hat Enterprise Linux 2.1
freetype-0:2.0.3-17.el21
Fixed · RHSA-2009:1062
Red Hat Enterprise Linux 3
freetype-0:2.1.4-12.el3
Fixed · RHSA-2009:0329
Red Hat Enterprise Linux 4
freetype-0:2.1.9-10.el4.7
Fixed · RHSA-2009:0329
Red Hat Enterprise Linux 5
freetype-0:2.2.1-21.el5_3
Fixed · RHSA-2009:1061
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 2.1 | freetype-0:2.0.3-17.el21 | Fixed | RHSA-2009:1062 |
| Red Hat Enterprise Linux 3 | freetype-0:2.1.4-12.el3 | Fixed | RHSA-2009:0329 |
| Red Hat Enterprise Linux 4 | freetype-0:2.1.9-10.el4.7 | Fixed | RHSA-2009:0329 |
| Red Hat Enterprise Linux 5 | freetype-0:2.2.1-21.el5_3 | Fixed | RHSA-2009:1061 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (42)
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=0545ec1ca36b27cb928128870a83e5f668980bc5 x_refsource_CONFIRMPatchThird Party Advisory
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=79972af4f0485a11dcb19551356c45245749fc5b x_refsource_CONFIRMPatchThird Party Advisory
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=a18788b14db60ae3673f932249cd02d33a227c4e x_refsource_CONFIRMPatchThird Party Advisory
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/tree/ChangeLog x_refsource_CONFIRMRelease NotesThird Party Advisory
- http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html vendor-advisoryx_refsource_APPLEMailing ListThird Party Advisory
- http://lists.apple.com/archives/security-announce/2009/May/msg00002.html vendor-advisoryx_refsource_APPLEMailing ListThird Party Advisory
- http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html vendor-advisoryx_refsource_APPLEBroken Link
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html vendor-advisoryx_refsource_APPLEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://secunia.com/advisories/34723 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/34913 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/34967 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35065 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35074 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35198 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35200 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35204 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35210 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/35379 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://security.gentoo.org/glsa/glsa-200905-05.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-270268-1 vendor-advisoryx_refsource_SUNALERTBroken Link
- http://support.apple.com/kb/HT3549 x_refsource_CONFIRMThird Party Advisory
- http://support.apple.com/kb/HT3613 x_refsource_CONFIRMThird Party Advisory
- http://support.apple.com/kb/HT3639 x_refsource_CONFIRMThird Party Advisory
- http://support.apple.com/kb/HT4435 x_refsource_CONFIRMBroken Link
- http://www.debian.org/security/2009/dsa-1784 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:243 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2009-0329.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1061.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1062.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.securityfocus.com/bid/34550 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-767-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA09-133A.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2009/1058 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2009/1297 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2009/1522 vdb-entryx_refsource_VUPENThird Party Advisory
- http://www.vupen.com/english/advisories/2009/1621 vdb-entryx_refsource_VUPENThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2009-0946 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=491384 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-0946
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10149 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2009-0946
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 17, 2009
Updated Aug 7, 2024
Reserved Mar 18, 2009
Link CVE-2009-0946
CISA Vulnrichment
Updated n/a