CVE-2015-9383

FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*

History

23 Feb 2023, 23:04

Type Values Removed Values Added
CPE cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
References (MLIST) https://lists.debian.org/debian-lts-announce/2019/09/msg00002.html - Third Party Advisory (MLIST) https://lists.debian.org/debian-lts-announce/2019/09/msg00002.html - Mailing List, Third Party Advisory
References (UBUNTU) https://usn.ubuntu.com/4126-2/ - (UBUNTU) https://usn.ubuntu.com/4126-2/ - Third Party Advisory
References (UBUNTU) https://usn.ubuntu.com/4126-1/ - (UBUNTU) https://usn.ubuntu.com/4126-1/ - Third Party Advisory

Information

Published : 2019-09-03 05:15

Updated : 2024-02-04 20:20


NVD link : CVE-2015-9383

Mitre link : CVE-2015-9383

CVE.ORG link : CVE-2015-9383


JSON object : View

Products Affected

debian

  • debian_linux

freetype

  • freetype

canonical

  • ubuntu_linux
CWE
CWE-125

Out-of-bounds Read