Integer overflow in FreeType - CVE-2023-2004

 

Integer overflow in FreeType - CVE-2023-2004

Published: May 9, 2023


Vulnerability identifier: #VU75888
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-2004
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow within the tt_hvadvance_adjust() function in src/truetype/ttgxvar.c. A remote attacker can pass specially crafted data to the application, trigger an integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

FreeType
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Fedora
Oracle Solaris
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Ubuntu
Isolation Segment
VMware Tanzu Application Service for VMs
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Sterling Connect:Direct Web Services
IBM Sterling Control Center
OpenJ9
VMware Tanzu Operations Manager
IBM Cloud Pak for Multicloud Management
CICS Transaction Gateway Desktop Edition
CICS Transaction Gateway for Multiplatforms
ObjectScale
OpenJDK Java (for Middleware)
libfreetype6 (Ubuntu package)
freetype-help
freetype-devel
freetype-debuginfo
freetype-debugsource
freetype
ftvalid
ftdiff
ftview
ftinspect
freetype2-debugsource
libfreetype6
libfreetype6-debuginfo
ftstring
ftmulti
ftdump
freetype2-devel
ftlint
ftbench
ftgamma
ftgrid
libfreetype6-32bit
libfreetype6-32bit-debuginfo
freetype2-devel-32bit
freetype2-profile-tti35
ft2demos
mingw-freetype
media-libs/freetype
chromium
Dell EMC VxRail Appliance

How to mitigate CVE-2023-2004

Install updates from vendor's website.

FreeType - update to 2.13.0
OpenJ9 - update to 0.38.0
IBM Cloud Pak for Multicloud Management - update to 2.3.8
OpenJDK Java (for Middleware) - addressed in versions 11.0.21, 17.0.9
ObjectScale - update to 1.4.0
libfreetype6 (Ubuntu package) - addressed in versions 2.10.1-2ubuntu0.3, 2.11.1+dfsg-1ubuntu0.2, 2.12.1+dfsg-3ubuntu0.1, 2.12.1+dfsg-4ubuntu0.1
freetype-help - update to 2.10.2-5
freetype-devel - update to 2.10.2-5
freetype-debuginfo - update to 2.10.2-5
freetype-debugsource - update to 2.10.2-5
freetype - update to 2.10.2-5
ftvalid - update to 2.10.4-150000.4.15.1
ftdiff - update to 2.10.4-150000.4.15.1
ftview - update to 2.10.4-150000.4.15.1
ftinspect - update to 2.10.4-150000.4.15.1
freetype2-debugsource - update to 2.10.4-150000.4.15.1
libfreetype6 - update to 2.10.4-150000.4.15.1
libfreetype6-debuginfo - update to 2.10.4-150000.4.15.1
ftstring - update to 2.10.4-150000.4.15.1
ftmulti - update to 2.10.4-150000.4.15.1
ftdump - update to 2.10.4-150000.4.15.1
freetype2-devel - update to 2.10.4-150000.4.15.1
ftlint - update to 2.10.4-150000.4.15.1
ftbench - update to 2.10.4-150000.4.15.1
ftgamma - update to 2.10.4-150000.4.15.1
ftgrid - update to 2.10.4-150000.4.15.1
libfreetype6-32bit - update to 2.10.4-150000.4.15.1
libfreetype6-32bit-debuginfo - update to 2.10.4-150000.4.15.1
freetype2-devel-32bit - update to 2.10.4-150000.4.15.1
freetype2-profile-tti35 - update to 2.10.4-150000.4.15.1
ft2demos - update to 2.10.4-150000.4.15.1
mingw-freetype - addressed in versions 2.12.1-2.fc36, 2.12.1-4.fc37, 2.12.1-4.fc38
media-libs/freetype - update to 2.13.0
freetype - update to 2.13.0-2
VMware Tanzu Operations Manager - update to 3.0.10
IBM Decision Optimization for Cloud Pak for Data - update to 4.7.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.24, 6.2.0.23, 6.3.0.7
IBM Sterling Control Center - addressed in versions 6.2.1.0.13, 6.3.1.0.2
Dell EMC VxRail Appliance - update to 8.0.120
chromium - addressed in versions 112.0.5615.49-1.el8, 112.0.5615.49-1.fc38, 112.0.5615.121-1.el7, 112.0.5615.121-1.el8, 112.0.5615.121-2.el9, 112.0.5615.121-2.fc36, 112.0.5615.121-2.fc37, 112.0.5615.121-2.fc38, 112.0.5615.165-1.el7, 112.0.5615.165-1.el8, 112.0.5615.165-1.el9, 112.0.5615.165-1.fc36, 112.0.5615.165-1.fc37, 112.0.5615.165-1.fc38

External References

Related Security Bulletins