Bug 753799 (CVE-2011-3439)

Summary: CVE-2011-3439 freetype: Multiple security flaws when loading CID-keyed Type 1 fonts
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: behdad, fonts-bugs, kevin, mkasik
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2012-02-02 22:51:15 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 753837, 754008, 754009, 754010, 754011, 754012, 785154, 806291, 889398    
Bug Blocks: 753800    

Description Jan Lieskovsky 2011-11-14 14:24:44 UTC
Multiple security flaws (multiple unsanitized invalid user input cases and one integer overflow flaw) were found in the way FreeType, the font rendering engine performed loading of CID-keyed (composite multibyte) Type 1 fonts. A remote attacker could provide a specially-crafted font file, which once opened in an application linked against freetype could lead to crash, or, potentially arbitrary code execution with the privileges of the user running the application.

References:
[1] http://support.apple.com/kb/HT5052
[2] https://bugzilla.novell.com/show_bug.cgi?id=730124

Comment 1 Jan Lieskovsky 2011-11-14 14:26:43 UTC
This issue affects the versions of the freetype package, as shipped with
Red Hat Enterprise Linux 4, 5, and 6.

--

This issue affects the versions of the freetype package, as shipped with Fedora release of 14, 15, and 16. Please schedule an update.

Comment 5 Jan Lieskovsky 2011-11-14 16:22:55 UTC
Created freetype tracking bugs for this issue

Affects: fedora-all [bug 753837]

Comment 8 errata-xmlrpc 2011-11-16 23:05:00 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 4
  Red Hat Enterprise Linux 5
  Red Hat Enterprise Linux 6

Via RHSA-2011:1455 https://rhn.redhat.com/errata/RHSA-2011-1455.html

Comment 10 errata-xmlrpc 2012-02-02 22:33:27 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5.6 EUS - Server Only

Via RHSA-2012:0094 https://rhn.redhat.com/errata/RHSA-2012-0094.html