Bug 621907 (CVE-2010-2808) - CVE-2010-2808 FreeType: Stack-based buffer overflow by processing certain LWFN fonts
Summary: CVE-2010-2808 FreeType: Stack-based buffer overflow by processing certain LWF...
Status: CLOSED ERRATA
Alias: CVE-2010-2808
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
(Show other bugs)
Version: unspecified
Hardware: All Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: public=20100805,reported=20100806,sou...
Keywords: Security
Depends On: 638140 638141 638142 638143 638522 638838 638839 806284
Blocks:
TreeView+ depends on / blocked
 
Reported: 2010-08-06 13:19 UTC by Jan Lieskovsky
Modified: 2016-03-04 11:44 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-07-29 12:50:51 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Proposed upstream patch (1.54 KB, patch)
2010-08-06 13:38 UTC, Jan Lieskovsky
no flags Details | Diff
Local copy of the reproducer (236.62 KB, application/postscript)
2010-08-06 13:41 UTC, Jan Lieskovsky
no flags Details


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2010:0737 normal SHIPPED_LIVE Important: freetype security update 2010-10-04 17:54:16 UTC
Red Hat Product Errata RHSA-2010:0864 normal SHIPPED_LIVE Important: freetype security update 2010-11-09 18:50:14 UTC

Description Jan Lieskovsky 2010-08-06 13:19:41 UTC
A stack-based buffer overflow was found in the way FreeType font
rendering engine processed certain Adobe Type 1 Mac Font File (LWFN)
fonts. An attacker could use this flaw to create a specially-crafted
font file that, when opened, would cause an application linked against
libfreetype to crash, or, possibly execute arbitrary code.

Upstream bug report:
  [1] https://savannah.nongnu.org/bugs/?30658

Public reproducer:
  [2] http://alt.swiecki.net/j/f/sigsegv31.ttf

Upstream changeset:
  [3] http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=81f3472c0ba7b8f6466e2e214fa8c1c17fade975

Credit: Robert Swiecki

Comment 1 Jan Lieskovsky 2010-08-06 13:35:25 UTC
This issue does NOT affect the version of the freetype package, as shipped
with Red Hat Enterprise Linux 3.

This issue affects the versions of the freetype package, as shipped
with Red Hat Enterprise Linux 4 and 5.

--

This issue affects the versions of the freetype package, as shipped
with Fedora release of 12 and 13.

Comment 2 Jan Lieskovsky 2010-08-06 13:38:45 UTC
Created attachment 437146 [details]
Proposed upstream patch

Comment 3 Jan Lieskovsky 2010-08-06 13:41:04 UTC
Created attachment 437147 [details]
Local copy of the reproducer

Comment 5 Jan Lieskovsky 2010-08-10 12:07:04 UTC
The CVE identifier of CVE-2010-2808 has been assigned to this.

Comment 9 Huzaifa S. Sidhpurwala 2010-09-29 09:05:51 UTC
Created freetype tracking bugs for this issue

Affects: fedora-all [bug 638522]

Comment 11 errata-xmlrpc 2010-10-04 17:54:27 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 4
  Red Hat Enterprise Linux 5

Via RHSA-2010:0737 https://rhn.redhat.com/errata/RHSA-2010-0737.html

Comment 12 errata-xmlrpc 2010-11-10 18:58:07 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2010:0864 https://rhn.redhat.com/errata/RHSA-2010-0864.html


Note You need to log in before you can comment on or make changes to this bug.