Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Debian: DSA-2388-1 Critical: T1lib Local Code Execution

debian
Calendar Grey January 15, 2012
Debian Logo
Explore the recent Debian security patch for t1lib addressing multiple potential code execution risks, and guidance on performing necessary upgrades.
Several vulnerabilities were discovered in t1lib, a Postscript Type 1 font rasterizer library, some of which might lead to code execution through the opening of files embedding bad...

Summary

Several vulnerabilities were discovered in t1lib, a Postscript Type 1
font rasterizer library, some of which might lead to code execution
through the opening of files embedding bad fonts.

CVE-2010-2642
A heap-based buffer overflow in the AFM font metrics parser
potentially leads to the execution of arbitrary code.

CVE-2011-0433
Another heap-based buffer overflow in the AFM font metrics
parser potentially leads to the execution of arbitrary code.

CVE-2011-0764
An invalid pointer dereference allows execution of arbitrary
code using crafted Type 1 fonts.

CVE-2011-1552
Another invalid pointer dereference results in an application
crash, triggered by crafted Type 1 fonts.

CVE-2011-1553
A use-after-free vulnerability results in an application
crash, triggered by crafted Type 1 fonts.

CVE-2011-1554
An off-by-one error results in an invalid memory read and
application crash, triggered by crafted Type 1 fonts.

For the oldstable distribution (lenny), this problem has been fixed in
version 5.1.2-3+lenny1.

...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: t1lib
CVE ID: CVE-2010-2642 CVE-2011-0433 CVE-2011-0764 CVE-2011-1552

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here