CVE-2015-9290

NONE EPSS 84.4%
Published Jul 30, 20196y ago · Modified Jun 17, 20262w ago
Find Similar
Published Jul 30, 2019 6y ago
Last Modified Jun 17, 2026 2w ago

Description

In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of cur and limit are sensible before going to Again.

Threat Intelligence

EPSS Exploit Probability
84.4% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available

Weaknesses 1

CWE-125 Out-of-bounds Read Memory Safety

Affected Products 1

VendorProductVersionRange
freetypefreetype* <2.6.1

References 5

  • git.savannah.gnu.org http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/src/type1/t1parse.c?id=e3058617f384cb6709f3878f753fa17aca9e3a30
    PatchThird Party Advisory
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2019/08/msg00019.html
  • savannah.nongnu.org https://savannah.nongnu.org/bugs/?45923
    ExploitThird Party Advisory
  • support.f5.com https://support.f5.com/csp/article/K38315305
  • support.f5.com https://support.f5.com/csp/article/K38315305?utm_source=f5support&amp%3Butm_medium=RSS

Remediation

  • git.savannah.gnu.org http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/src/type1/t1parse.c?id=e3058617f384cb6709f3878f753fa17aca9e3a30
    PatchThird Party Advisory