Description
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted property data in a BDF font.
Affected products
- FreeType / FreeType2.4.8
- FreeType / FreeType1.3.1 – 1.3.1
- FreeType / FreeType2.0.0 – 2.0.0
- FreeType / FreeType2.0.1 – 2.0.1
- FreeType / FreeType2.0.2 – 2.0.2
- FreeType / FreeType2.0.3 – 2.0.3
- FreeType / FreeType2.0.4 – 2.0.4
- FreeType / FreeType2.0.5 – 2.0.5
- FreeType / FreeType2.0.6 – 2.0.6
- FreeType / FreeType2.0.7 – 2.0.7
- FreeType / FreeType2.0.8 – 2.0.8
- FreeType / FreeType2.0.9 – 2.0.9
- FreeType / FreeType2.1 – 2.1
- FreeType / FreeType2.1.3 – 2.1.3
- FreeType / FreeType2.1.4 – 2.1.4
- FreeType / FreeType2.1.5 – 2.1.5
- FreeType / FreeType2.1.6 – 2.1.6
- FreeType / FreeType2.1.7 – 2.1.7
- FreeType / FreeType2.1.8 – 2.1.8
- FreeType / FreeType2.1.8 – 2.1.8
- FreeType / FreeType2.1.9 – 2.1.9
- FreeType / FreeType2.1.10 – 2.1.10
- FreeType / FreeType2.2.0 – 2.2.0
- FreeType / FreeType2.2.1 – 2.2.1
- FreeType / FreeType2.3.0 – 2.3.0
- FreeType / FreeType2.3.1 – 2.3.1
- FreeType / FreeType2.3.2 – 2.3.2
- FreeType / FreeType2.3.3 – 2.3.3
- FreeType / FreeType2.3.4 – 2.3.4
- FreeType / FreeType2.3.5 – 2.3.5
- FreeType / FreeType2.3.6 – 2.3.6
- FreeType / FreeType2.3.7 – 2.3.7
- FreeType / FreeType2.3.8 – 2.3.8
- FreeType / FreeType2.3.9 – 2.3.9
- FreeType / FreeType2.3.10 – 2.3.10
- FreeType / FreeType2.3.11 – 2.3.11
- FreeType / FreeType2.3.12 – 2.3.12
- FreeType / FreeType2.4.0 – 2.4.0
- FreeType / FreeType2.4.1 – 2.4.1
- FreeType / FreeType2.4.2 – 2.4.2
- FreeType / FreeType2.4.3 – 2.4.3
- FreeType / FreeType2.4.4 – 2.4.4
- FreeType / FreeType2.4.5 – 2.4.5
- FreeType / FreeType2.4.6 – 2.4.6
- FreeType / FreeType2.4.7 – 2.4.7
- Mozilla / firefox_mobile10.0.3
- Mozilla / firefox_mobile1.0 – 1.0
- Mozilla / firefox_mobile4.0 – 4.0
- Mozilla / firefox_mobile4.0 – 4.0
- Mozilla / firefox_mobile4.0 – 4.0
- Mozilla / firefox_mobile4.0 – 4.0
- Mozilla / firefox_mobile4.0 – 4.0
- Mozilla / firefox_mobile5.0 – 5.0
- Mozilla / firefox_mobile6.0 – 6.0
- Mozilla / firefox_mobile6.0.1 – 6.0.1
- Mozilla / firefox_mobile6.0.2 – 6.0.2
- Mozilla / firefox_mobile7.0 – 7.0
- Mozilla / firefox_mobile8.0 – 8.0
- Mozilla / firefox_mobile9.0 – 9.0
- Mozilla / firefox_mobile10.0 – 10.0
- Mozilla / firefox_mobile10.0.1 – 10.0.1
- Mozilla / firefox_mobile10.0.2 – 10.0.2
References
- VENDOR_ADVISORYhttp://secunia.com/advisories/48797
- VENDOR_ADVISORYhttp://secunia.com/advisories/48508
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=800581
- VENDOR_ADVISORYhttp://secunia.com/advisories/48822
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDVSA-2012:057
- MAILING_LISThttp://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/48758
- VENDOR_ADVISORYhttp://support.apple.com/kb/HT5503
- MISChttp://www.securityfocus.com/bid/52318
- VENDOR_ADVISORYhttp://www.ubuntu.com/usn/USN-1403-1
- MISChttps://bugzilla.mozilla.org/show_bug.cgi?id=733512
- VENDOR_ADVISORYhttp://secunia.com/advisories/48918
- MAILING_LISThttp://www.openwall.com/lists/oss-security/2012/03/06/16
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00003.html
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00015.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/48973
- MISChttp://www.mozilla.org/security/announce/2012/mfsa2012-21.html
- MISChttp://rhn.redhat.com/errata/RHSA-2012-0467.html
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00002.html
- MISChttp://www.securitytracker.com/id?1026765
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00004.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/48951
- MISChttp://security.gentoo.org/glsa/glsa-201204-04.xml