Bug 621907 - (CVE-2010-2808) CVE-2010-2808 FreeType: Stack-based buffer overflow by processing certain LWFN fonts
CVE-2010-2808 FreeType: Stack-based buffer overflow by processing certain LWF...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
public=20100805,reported=20100806,sou...
: Security
Depends On: 638140 638141 638142 638143 638522 638838 638839 806284
Blocks:
  Show dependency treegraph
 
Reported: 2010-08-06 09:19 EDT by Jan Lieskovsky
Modified: 2016-03-04 06:44 EST (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-07-29 08:50:51 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)
Proposed upstream patch (1.54 KB, patch)
2010-08-06 09:38 EDT, Jan Lieskovsky
no flags Details | Diff
Local copy of the reproducer (236.62 KB, application/postscript)
2010-08-06 09:41 EDT, Jan Lieskovsky
no flags Details

  None (edit)
Description Jan Lieskovsky 2010-08-06 09:19:41 EDT
A stack-based buffer overflow was found in the way FreeType font
rendering engine processed certain Adobe Type 1 Mac Font File (LWFN)
fonts. An attacker could use this flaw to create a specially-crafted
font file that, when opened, would cause an application linked against
libfreetype to crash, or, possibly execute arbitrary code.

Upstream bug report:
  [1] https://savannah.nongnu.org/bugs/?30658

Public reproducer:
  [2] http://alt.swiecki.net/j/f/sigsegv31.ttf

Upstream changeset:
  [3] http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=81f3472c0ba7b8f6466e2e214fa8c1c17fade975

Credit: Robert Swiecki
Comment 1 Jan Lieskovsky 2010-08-06 09:35:25 EDT
This issue does NOT affect the version of the freetype package, as shipped
with Red Hat Enterprise Linux 3.

This issue affects the versions of the freetype package, as shipped
with Red Hat Enterprise Linux 4 and 5.

--

This issue affects the versions of the freetype package, as shipped
with Fedora release of 12 and 13.
Comment 2 Jan Lieskovsky 2010-08-06 09:38:45 EDT
Created attachment 437146 [details]
Proposed upstream patch
Comment 3 Jan Lieskovsky 2010-08-06 09:41:04 EDT
Created attachment 437147 [details]
Local copy of the reproducer
Comment 5 Jan Lieskovsky 2010-08-10 08:07:04 EDT
The CVE identifier of CVE-2010-2808 has been assigned to this.
Comment 9 Huzaifa S. Sidhpurwala 2010-09-29 05:05:51 EDT
Created freetype tracking bugs for this issue

Affects: fedora-all [bug 638522]
Comment 11 errata-xmlrpc 2010-10-04 13:54:27 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 4
  Red Hat Enterprise Linux 5

Via RHSA-2010:0737 https://rhn.redhat.com/errata/RHSA-2010-0737.html
Comment 12 errata-xmlrpc 2010-11-10 13:58:07 EST
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2010:0864 https://rhn.redhat.com/errata/RHSA-2010-0864.html

Note You need to log in before you can comment on or make changes to this bug.