Bug 621907 (CVE-2010-2808)

Summary: CVE-2010-2808 FreeType: Stack-based buffer overflow by processing certain LWFN fonts
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: mkasik, security-response-team, vkrizan
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-07-29 12:50:51 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 638140, 638141, 638142, 638143, 638522, 638838, 638839, 806284    
Bug Blocks:    
Attachments:
Description Flags
Proposed upstream patch
none
Local copy of the reproducer none

Description Jan Lieskovsky 2010-08-06 13:19:41 UTC
A stack-based buffer overflow was found in the way FreeType font
rendering engine processed certain Adobe Type 1 Mac Font File (LWFN)
fonts. An attacker could use this flaw to create a specially-crafted
font file that, when opened, would cause an application linked against
libfreetype to crash, or, possibly execute arbitrary code.

Upstream bug report:
  [1] https://savannah.nongnu.org/bugs/?30658

Public reproducer:
  [2] http://alt.swiecki.net/j/f/sigsegv31.ttf

Upstream changeset:
  [3] http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=81f3472c0ba7b8f6466e2e214fa8c1c17fade975

Credit: Robert Swiecki

Comment 1 Jan Lieskovsky 2010-08-06 13:35:25 UTC
This issue does NOT affect the version of the freetype package, as shipped
with Red Hat Enterprise Linux 3.

This issue affects the versions of the freetype package, as shipped
with Red Hat Enterprise Linux 4 and 5.

--

This issue affects the versions of the freetype package, as shipped
with Fedora release of 12 and 13.

Comment 2 Jan Lieskovsky 2010-08-06 13:38:45 UTC
Created attachment 437146 [details]
Proposed upstream patch

Comment 3 Jan Lieskovsky 2010-08-06 13:41:04 UTC
Created attachment 437147 [details]
Local copy of the reproducer

Comment 5 Jan Lieskovsky 2010-08-10 12:07:04 UTC
The CVE identifier of CVE-2010-2808 has been assigned to this.

Comment 9 Huzaifa S. Sidhpurwala 2010-09-29 09:05:51 UTC
Created freetype tracking bugs for this issue

Affects: fedora-all [bug 638522]

Comment 11 errata-xmlrpc 2010-10-04 17:54:27 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 4
  Red Hat Enterprise Linux 5

Via RHSA-2010:0737 https://rhn.redhat.com/errata/RHSA-2010-0737.html

Comment 12 errata-xmlrpc 2010-11-10 18:58:07 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2010:0864 https://rhn.redhat.com/errata/RHSA-2010-0864.html