Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-9381

Опубликовано: 17 сент. 2019
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5freetypeOut of support scope
Red Hat Enterprise Linux 8freetypeNot affected
Red Hat Enterprise Linux 6freetypeFixedRHSA-2019:425417.12.2019
Red Hat Enterprise Linux 7accountsserviceFixedRHSA-2018:314030.10.2018
Red Hat Enterprise Linux 7adwaita-icon-themeFixedRHSA-2018:314030.10.2018
Red Hat Enterprise Linux 7appstream-dataFixedRHSA-2018:314030.10.2018
Red Hat Enterprise Linux 7atkFixedRHSA-2018:314030.10.2018
Red Hat Enterprise Linux 7at-spi2-atkFixedRHSA-2018:314030.10.2018
Red Hat Enterprise Linux 7at-spi2-coreFixedRHSA-2018:314030.10.2018
Red Hat Enterprise Linux 7baobabFixedRHSA-2018:314030.10.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1752788freetype: a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c leading to crash

EPSS

Процентиль: 72%
0.00711
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 6 лет назад

FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c.

CVSS3: 8.8
nvd
больше 6 лет назад

FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c.

CVSS3: 8.8
debian
больше 6 лет назад

FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Priv ...

CVSS3: 8.8
github
больше 3 лет назад

FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c.

oracle-oval
около 6 лет назад

ELSA-2019-4254: freetype security update (MODERATE)

EPSS

Процентиль: 72%
0.00711
Низкий

6.5 Medium

CVSS3