HIGH · 7.5

CVE-2009-0946

Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcma...

Vulnerability Description

Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
FreetypeFreetype<= 2.3.9
DebianDebian Linux4.0
CanonicalUbuntu Linux6.06
OpensuseOpensuse10.3
SuseLinux Enterprise Server10
AppleSafari4.0
AppleIphone Os>= 1.0.0, <= 2.2.1
AppleMac Os X>= 10.6.0, <= 10.6.4
AppleMac Os X Server>= 10.6.0, <= 10.6.4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-0946?

CVE-2009-0946 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcma...

How severe is CVE-2009-0946?

CVE-2009-0946 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-0946?

Check the references section above for vendor advisories and patch information. Affected products include: Freetype Freetype, Debian Debian Linux, Canonical Ubuntu Linux, Opensuse Opensuse, Suse Linux Enterprise Server.