Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-1129

Опубликовано: 23 фев. 2012
Источник: redhat
CVSS2: 2.6

Описание

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted SFNT string in a Type 42 font.

Отчет

This bug is not a security issue. For detailed explanation, refer to: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-1129#c5

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5freetypeNot affected
Red Hat Enterprise Linux 6freetypeNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-193
https://bugzilla.redhat.com/show_bug.cgi?id=800585freetype: heap off-by-one buffer underflow in Type42 parser t42_parse_sfnts() (#35602)

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
почти 14 лет назад

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted SFNT string in a Type 42 font.

nvd
почти 14 лет назад

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted SFNT string in a Type 42 font.

debian
почти 14 лет назад

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 ...

github
больше 3 лет назад

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted SFNT string in a Type 42 font.

fstec
почти 14 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

2.6 Low

CVSS2