Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-9382

Опубликовано: 03 сент. 2019
Источник: redhat
CVSS3: 4.3

Описание

FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face operation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5freetypeOut of support scope
Red Hat Enterprise Linux 6chromium-browserAffected
Red Hat Enterprise Linux 6firefoxAffected
Red Hat Enterprise Linux 6thunderbirdWill not fix
Red Hat Enterprise Linux 8freetypeNot affected
Red Hat Enterprise Linux 6freetypeFixedRHSA-2019:425417.12.2019
Red Hat Enterprise Linux 7accountsserviceFixedRHSA-2018:314030.10.2018
Red Hat Enterprise Linux 7adwaita-icon-themeFixedRHSA-2018:314030.10.2018
Red Hat Enterprise Linux 7appstream-dataFixedRHSA-2018:314030.10.2018
Red Hat Enterprise Linux 7atkFixedRHSA-2018:314030.10.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=1763609freetype: mishandling ps_parser_skip_PS_token in an FT_New_Memory_Face operation in skip_comment, psaux/psobjs.c, leads to a buffer over-read

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 6 лет назад

FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face operation.

CVSS3: 6.5
nvd
больше 6 лет назад

FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face operation.

CVSS3: 6.5
debian
больше 6 лет назад

FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/ ...

CVSS3: 6.5
github
больше 3 лет назад

FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face operation.

oracle-oval
около 6 лет назад

ELSA-2019-4254: freetype security update (MODERATE)

4.3 Medium

CVSS3