CVE-2012-5669
freetype: heap buffer over-read in BDF parsing _bdf_parse_glyphs() (#37906)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to BDF fonts and an incorrect calculation that triggers an out-of-bounds read.
La función _bdf_parse_glyphs en FreeType anterior a v2.4.11, permite a atacantes dependientes del contexto provocar una denegación de servicio (Caída) u posiblemente la ejecución de código arbitrario a través de vectores relacionados con las fuentes BDF y un cálculo incorrecto que provoca una lectura fuera de rango.
A null pointer de-reference flaw was found in the way Freetype font rendering engine handled Glyph bitmap distribution format fonts. A remote attacker could provide a specially-crafted BDF font file, which once processed in an application linked against FreeType would lead to that application crash. An out-of heap-based buffer read flaw was found in the way FreeType font rendering engine performed parsing of glyph information and relevant bitmaps for glyph bitmap distribution format (BDF). A remote attacker could provide a specially-crafted BDF font file, which once opened in an application linked against FreeType would lead to that application crash. An out-of heap-based buffer write flaw was found in the way FreeType font rendering engine performed parsing of glyph information and relevant bitmaps for glyph bitmap distribution format (BDF). A remote attacker could provide a specially-crafted font file, which once opened in an application linked against FreeType would lead to that application crash, or, potentially, arbitrary code execution with the privileges of the user running the application.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-10-24 CVE Reserved
- 2013-01-15 CVE Published
- 2024-08-06 CVE Updated
- 2025-07-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (15)
URL | Tag | Source |
---|---|---|
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=07bdb6e289c7954e2a533039dc93c1c136099d2d | X_refsource_confirm | |
http://www.freetype.org | X_refsource_confirm | |
http://www.openwall.com/lists/oss-security/2012/12/25/2 | Mailing List |
|
http://www.securitytracker.com/id?1027921 | Vdb Entry | |
https://savannah.nongnu.org/bugs/?37906 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | <= 2.4.10 Search vendor "Freetype" for product "Freetype" and version " <= 2.4.10" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 1.3.1 Search vendor "Freetype" for product "Freetype" and version "1.3.1" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.0.0 Search vendor "Freetype" for product "Freetype" and version "2.0.0" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.0.1 Search vendor "Freetype" for product "Freetype" and version "2.0.1" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.0.2 Search vendor "Freetype" for product "Freetype" and version "2.0.2" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.0.3 Search vendor "Freetype" for product "Freetype" and version "2.0.3" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.0.4 Search vendor "Freetype" for product "Freetype" and version "2.0.4" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.0.5 Search vendor "Freetype" for product "Freetype" and version "2.0.5" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.0.6 Search vendor "Freetype" for product "Freetype" and version "2.0.6" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.0.7 Search vendor "Freetype" for product "Freetype" and version "2.0.7" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.0.8 Search vendor "Freetype" for product "Freetype" and version "2.0.8" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.0.9 Search vendor "Freetype" for product "Freetype" and version "2.0.9" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.1 Search vendor "Freetype" for product "Freetype" and version "2.1" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.1.3 Search vendor "Freetype" for product "Freetype" and version "2.1.3" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.1.4 Search vendor "Freetype" for product "Freetype" and version "2.1.4" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.1.5 Search vendor "Freetype" for product "Freetype" and version "2.1.5" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.1.6 Search vendor "Freetype" for product "Freetype" and version "2.1.6" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.1.7 Search vendor "Freetype" for product "Freetype" and version "2.1.7" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.1.8 Search vendor "Freetype" for product "Freetype" and version "2.1.8" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.1.8 Search vendor "Freetype" for product "Freetype" and version "2.1.8" | rc1 |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.1.9 Search vendor "Freetype" for product "Freetype" and version "2.1.9" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.1.10 Search vendor "Freetype" for product "Freetype" and version "2.1.10" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.2.0 Search vendor "Freetype" for product "Freetype" and version "2.2.0" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.2.1 Search vendor "Freetype" for product "Freetype" and version "2.2.1" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.3.0 Search vendor "Freetype" for product "Freetype" and version "2.3.0" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.3.1 Search vendor "Freetype" for product "Freetype" and version "2.3.1" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.3.2 Search vendor "Freetype" for product "Freetype" and version "2.3.2" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.3.3 Search vendor "Freetype" for product "Freetype" and version "2.3.3" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.3.4 Search vendor "Freetype" for product "Freetype" and version "2.3.4" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.3.5 Search vendor "Freetype" for product "Freetype" and version "2.3.5" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.3.6 Search vendor "Freetype" for product "Freetype" and version "2.3.6" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.3.7 Search vendor "Freetype" for product "Freetype" and version "2.3.7" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.3.8 Search vendor "Freetype" for product "Freetype" and version "2.3.8" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.3.9 Search vendor "Freetype" for product "Freetype" and version "2.3.9" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.3.10 Search vendor "Freetype" for product "Freetype" and version "2.3.10" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.3.11 Search vendor "Freetype" for product "Freetype" and version "2.3.11" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.3.12 Search vendor "Freetype" for product "Freetype" and version "2.3.12" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.4.0 Search vendor "Freetype" for product "Freetype" and version "2.4.0" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.4.1 Search vendor "Freetype" for product "Freetype" and version "2.4.1" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.4.2 Search vendor "Freetype" for product "Freetype" and version "2.4.2" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.4.3 Search vendor "Freetype" for product "Freetype" and version "2.4.3" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.4.4 Search vendor "Freetype" for product "Freetype" and version "2.4.4" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.4.5 Search vendor "Freetype" for product "Freetype" and version "2.4.5" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.4.6 Search vendor "Freetype" for product "Freetype" and version "2.4.6" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.4.7 Search vendor "Freetype" for product "Freetype" and version "2.4.7" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.4.8 Search vendor "Freetype" for product "Freetype" and version "2.4.8" | - |
Affected
| ||||||
Freetype Search vendor "Freetype" | Freetype Search vendor "Freetype" for product "Freetype" | 2.4.9 Search vendor "Freetype" for product "Freetype" and version "2.4.9" | - |
Affected
|