Executive Summary

Summary
Titlet1lib security update
Informations
NameDSA-2388First vendor Publication2012-01-14
VendorDebianLast vendor Modification2012-01-14
Severity (Vendor) N/ARevision1

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:H/Au:N/C:C/I:C/A:C)
Cvss Base Score7.6Attack RangeNetwork
Cvss Impact Score10Attack ComplexityHigh
Cvss Expoit Score4.9AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Several vulnerabilities were discovered in t1lib, a Postscript Type 1 font rasterizer library, some of which might lead to code execution through the opening of files embedding bad fonts.

CVE-2010-2642 A heap-based buffer overflow in the AFM font metrics parser potentially leads to the execution of arbitrary code.

CVE-2011-0433 Another heap-based buffer overflow in the AFM font metrics parser potentially leads to the execution of arbitrary code.

CVE-2011-0764 An invalid pointer dereference allows execution of arbitrary code using crafted Type 1 fonts.

CVE-2011-1552 Another invalid pointer dereference results in an application crash, triggered by crafted Type 1 fonts.

CVE-2011-1553 A use-after-free vulnerability results in an application crash, triggered by crafted Type 1 fonts.

CVE-2011-1554 An off-by-one error results in an invalid memory read and application crash, triggered by crafted Type 1 fonts.

For the oldstable distribution (lenny), this problem has been fixed in version 5.1.2-3+lenny1.

For the stable distribution (squeeze), this problem has been fixed in version 5.1.2-3+squeeze1.

For the testing distribution (wheezy), this problem has been fixed in version 5.1.2-3.3.

For the unstable distribution (sid), this problem has been fixed in version 5.1.2-3.3.

We recommend that you upgrade your t1lib packages.

Original Source

Url : http://www.debian.org/security/2012/dsa-2388

CWE : Common Weakness Enumeration

idName
CWE-119Failure to Constrain Operations within the Bounds of a Memory Buffer
CWE-399Resource Management Errors
CWE-189Numeric Errors
CWE-20Improper Input Validation

CPE : Common Platform Enumeration

TypeDescriptionCount
Application40
Application1
Application34
Application25
Application1
Application1

Open Source Vulnerability Database (OSVDB)

idDescription
74729Evince DVI File AFM Font Parsing Overflow
74528t1lib PDF Type 1 Font Handling Invalid Memory Write Use-after-free DoS
74527t1lib PDF Type 1 Font Handling Invalid Memory Location DoS
74526t1lib PDF Type 1 Font Handling Off-by-one Overflow DoS
72302t1lib PDF Type 1 Font Handling Invalid Pointer Code Execution
70302Evince backend/dvi/mdvi-lib/afmparse.c token() Function Overflow

Alert History

If you want to see full details history, please login or register.
0
DateInformations
2012-11-19 13:20:02
  • Multiple Updates