Bug 867620 (CVE-2014-2240) - VUL-0: CVE-2014-2240 CVE-2014-2241: freetype2: problems in CFF rasterizer
Summary: VUL-0: CVE-2014-2240 CVE-2014-2241: freetype2: problems in CFF rasterizer
Status: RESOLVED FIXED
Alias: CVE-2014-2240
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 13.1
: P3 - Medium : Major
Target Milestone: ---
Assignee: Vladimir Nadvornik
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-03-10 15:40 UTC by Marcus Meissner
Modified: 2019-05-22 00:58 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2014-03-10 15:40:42 UTC
public, via oss-sec and freetype2 2.5.3 release

From: Raphael Geissert <geissert@debian.org>
Date: Mon, 10 Mar 2014 16:31:33 +0100
Subject: [oss-security] Two stack-based issues in freetype [NOT a request]


Just a heads up as I've not seen this issue anywhere. There is an
"Out-of-bounds stack-based read/write in cf2_hintmap_build" in freetype

If I understood things correctly, CVE-2014-2240 is:
https://savannah.nongnu.org/bugs/?41697#comment0
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=0eae6eb0645264c98812f0095e0f5df4541830e6

While CVE-2014-2241 is:
https://savannah.nongnu.org/bugs/?41697#comment2
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=135c3faebb96f8f550bd4f318716f2e1e095a969

Release notes:
http://sourceforge.net/projects/freetype/files/freetype2/2.5.3/
Comment 1 Marcus Meissner 2014-03-10 15:42:47 UTC
The pieces of code do not seem to exist in the SLE11 freetype2 2.3.7.
Comment 2 Swamp Workflow Management 2014-03-10 23:00:23 UTC
bugbot adjusting priority
Comment 3 Forgotten User DV81ZEWZkN 2014-03-10 23:07:58 UTC
if memory serves me correctly, cff engine is part of freetype with 13.1 and newer - will check and try to backport fixes accordingly.
Comment 4 Marcus Meissner 2014-03-13 07:40:03 UTC
so openSUSE only, no need for SLE update.
Comment 9 Andreas Taschner 2014-03-31 13:51:35 UTC
Thank you very much for quick clarification, Marcus !
Comment 10 Marcus Meissner 2014-05-05 14:35:12 UTC
done I think? or stuff for opensuse missing?