Red Hat Bugzilla – Bug 815022
CVE-2012-0472 Mozilla: Potential memory corruption during font rendering using cairo-dwrite (MFSA 2012-25)
Last modified: 2012-04-24 17:01:44 EDT
Security research firm iDefense reported that researcher wushi of team509 discovered a memory corruption on Windows Vista and Windows 7 systems with hardware acceleration disabled or using incompatible video drivers. This is created by using cairo-dwrite to attempt to render fonts on an unsupported code path. This corruption causes a potentially exploitable crash on affected systems. This issue also seems to affect the linux version of firefox and thunderbird. Reference: http://www.mozilla.org/security/announce/2012/mfsa2012-25.html
Acknowledgements: Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges wushi of team509 via iDefense as the original reporter.
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6 Via RHSA-2012:0516 https://rhn.redhat.com/errata/RHSA-2012-0516.html
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6 Via RHSA-2012:0515 https://rhn.redhat.com/errata/RHSA-2012-0515.html