Integer overflow in FreeType - CVE-2023-2004
Published: May 9, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow within the tt_hvadvance_adjust() function in src/truetype/ttgxvar.c. A remote attacker can pass specially crafted data to the application, trigger an integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Fedora
Oracle Solaris
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Ubuntu
Isolation Segment
VMware Tanzu Application Service for VMs
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Sterling Connect:Direct Web Services
IBM Sterling Control Center
OpenJ9
VMware Tanzu Operations Manager
IBM Cloud Pak for Multicloud Management
CICS Transaction Gateway Desktop Edition
CICS Transaction Gateway for Multiplatforms
ObjectScale
OpenJDK Java (for Middleware)
libfreetype6 (Ubuntu package)
freetype-help
freetype-devel
freetype-debuginfo
freetype-debugsource
freetype
ftvalid
ftdiff
ftview
ftinspect
freetype2-debugsource
libfreetype6
libfreetype6-debuginfo
ftstring
ftmulti
ftdump
freetype2-devel
ftlint
ftbench
ftgamma
ftgrid
libfreetype6-32bit
libfreetype6-32bit-debuginfo
freetype2-devel-32bit
freetype2-profile-tti35
ft2demos
mingw-freetype
media-libs/freetype
chromium
Dell EMC VxRail Appliance
How to mitigate CVE-2023-2004
OpenJ9 - update to 0.38.0
IBM Cloud Pak for Multicloud Management - update to 2.3.8
OpenJDK Java (for Middleware) - addressed in versions 11.0.21, 17.0.9
ObjectScale - update to 1.4.0
libfreetype6 (Ubuntu package) - addressed in versions 2.10.1-2ubuntu0.3, 2.11.1+dfsg-1ubuntu0.2, 2.12.1+dfsg-3ubuntu0.1, 2.12.1+dfsg-4ubuntu0.1
freetype-help - update to 2.10.2-5
freetype-devel - update to 2.10.2-5
freetype-debuginfo - update to 2.10.2-5
freetype-debugsource - update to 2.10.2-5
freetype - update to 2.10.2-5
ftvalid - update to 2.10.4-150000.4.15.1
ftdiff - update to 2.10.4-150000.4.15.1
ftview - update to 2.10.4-150000.4.15.1
ftinspect - update to 2.10.4-150000.4.15.1
freetype2-debugsource - update to 2.10.4-150000.4.15.1
libfreetype6 - update to 2.10.4-150000.4.15.1
libfreetype6-debuginfo - update to 2.10.4-150000.4.15.1
ftstring - update to 2.10.4-150000.4.15.1
ftmulti - update to 2.10.4-150000.4.15.1
ftdump - update to 2.10.4-150000.4.15.1
freetype2-devel - update to 2.10.4-150000.4.15.1
ftlint - update to 2.10.4-150000.4.15.1
ftbench - update to 2.10.4-150000.4.15.1
ftgamma - update to 2.10.4-150000.4.15.1
ftgrid - update to 2.10.4-150000.4.15.1
libfreetype6-32bit - update to 2.10.4-150000.4.15.1
libfreetype6-32bit-debuginfo - update to 2.10.4-150000.4.15.1
freetype2-devel-32bit - update to 2.10.4-150000.4.15.1
freetype2-profile-tti35 - update to 2.10.4-150000.4.15.1
ft2demos - update to 2.10.4-150000.4.15.1
mingw-freetype - addressed in versions 2.12.1-2.fc36, 2.12.1-4.fc37, 2.12.1-4.fc38
media-libs/freetype - update to 2.13.0
freetype - update to 2.13.0-2
VMware Tanzu Operations Manager - update to 3.0.10
IBM Decision Optimization for Cloud Pak for Data - update to 4.7.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.24, 6.2.0.23, 6.3.0.7
IBM Sterling Control Center - addressed in versions 6.2.1.0.13, 6.3.1.0.2
Dell EMC VxRail Appliance - update to 8.0.120
chromium - addressed in versions 112.0.5615.49-1.el8, 112.0.5615.49-1.fc38, 112.0.5615.121-1.el7, 112.0.5615.121-1.el8, 112.0.5615.121-2.el9, 112.0.5615.121-2.fc36, 112.0.5615.121-2.fc37, 112.0.5615.121-2.fc38, 112.0.5615.165-1.el7, 112.0.5615.165-1.el8, 112.0.5615.165-1.el9, 112.0.5615.165-1.fc36, 112.0.5615.165-1.fc37, 112.0.5615.165-1.fc38
External References
- https://bugzilla.redhat.com/show_bug.cgi?id=2186428
- https://access.redhat.com/security/cve/CVE-2023-2004
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50462
- https://github.com/freetype/freetype/commit/e6fda039ad638866b7a6a5d046f03278ba1b7611
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NGWWGQULJ7QRNP4GY57HE7OO7VMRWMPN/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FEJZMAUB4XP44HSHEBDWEKFGA7DUHY42/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4AOSGAOPXLBK4A5ZRTVZ4M6QKVLSWMWG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RJQI63HWZFL6M26Q6UOHKDY6LD2PFC5Z/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KDNGTGQAUZJ6YQDI2AVGYIFFPUMMZLKS/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VRSEIYMPWLVPGTC34N2Q3WAUHGGOWSWP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SFZWDF43D73C5KWFF26GIIVZJKEFPS3K/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IHHD6KNH4WLUE6JG6HRQZWNAJMHJ32X7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SLO7BL2MHZYPY6O3OAEAQL3SKYMGGO6M/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ES2CDRHR2Y4WY6DNDIAPYZFXJU3ZBFAV/
Related Security Bulletins
- Remote code execution in Freetype
- Ubuntu update for freetype
- Eclipse OpenJ9 update for FreeType
- VMware Tanzu products update for FreeType
- Fedora 38 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora 37 update for mingw-freetype
- Fedora 38 update for mingw-freetype
- Fedora 36 update for mingw-freetype
- Fedora EPEL 9 update for chromium
- Fedora 38 update for chromium
- Fedora 37 update for chromium
- Fedora EPEL 7 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora 36 update for chromium
- Fedora EPEL 7 update for chromium
- Fedora EPEL 9 update for chromium
- Fedora 38 update for chromium
- Fedora 36 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora 37 update for chromium
- Multiple vulnerabilities in Oracle Solaris third-party software
- SUSE update for freetype2
- Multiple vulnerabilities in IBM Decision Optimization for Cloud Pak for Data
- Red Hat OpenJDK 17.0 update for portable Linux builds
- Red Hat OpenJDK 11.0 update for portable Linux builds
- Gentoo update for FreeType
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- Multiple vulnerabilities in IBM CICS Transaction Gateway for Multiplatforms
- Multiple vulnerabilities in IBM CICS Transaction Gateway Desktop Edition
- openEuler update for freetype
- Multiple vulnerabilities in IBM Sterling Connect:Direct Web Services
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM Sterling Control Center
- Amazon Linux AMI update for freetype
- Multiple vulnerabilities in IBM Knowledge Catalog for IBM Cloud Pak for Data