Bug 1149397 (CVE-2015-9383) - VUL-1: CVE-2015-9383: freetype2: heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c
Summary: VUL-1: CVE-2015-9383: freetype2: heap-based buffer over-read in tt_cmap14_val...
Status: RESOLVED FIXED
Alias: CVE-2015-9383
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/241649/
Whiteboard: CVSSv3:SUSE:CVE-2015-9383:4.4:(AV:L/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2019-09-04 13:16 UTC by Alexandros Toptsoglou
Modified: 2024-05-06 12:46 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Alexandros Toptsoglou 2019-09-04 14:41:36 UTC
cmap type 14 introduced in version 2.3.6 [0] and fixed in 2.6.2.
Based on this tracked as affected 

SLE-11:Update and SLE-12:Update

The fix is available at [1] and instructions including with attachments for reproducing at [2]. 

My attempt to reproduce the issue was not successful. 

[0] https://github.com/aseprite/freetype2/commit/9a966b7d1bbc9e35eddb68136b73cbe006dff675
[1] http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=57cbb8c148999ba8f14ed53435fc071ac9953afd
[2] https://savannah.nongnu.org/bugs/?46346
Comment 3 Thomas Leroy 2024-05-06 12:46:37 UTC
All done, closing.