ISOMAN

CVE

CVE-2015-3905

Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.39 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.

Severity
HIGH
CVSS
7.5
Published
Modified

Linked Releases

References

  1. http://ubuntu.com/usn/usn-2627-1
  2. http://www.openwall.com/lists/oss-security/2015/05/13/9
  3. http://www.openwall.com/lists/oss-security/2015/05/22/10
  4. http://www.securityfocus.com/bid/74674
  5. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=779274
  6. https://bugzilla.redhat.com/show_bug.cgi?id=1218365
  7. https://github.com/kohler/t1utils/blob/master/NEWS
  8. https://github.com/kohler/t1utils/commit/6b9d1aafcb61a3663c883663eb19ccdbfcde8d33
  9. https://github.com/kohler/t1utils/issues/4
  10. https://security.gentoo.org/glsa/201507-10
  11. http://ubuntu.com/usn/usn-2627-1
  12. http://www.openwall.com/lists/oss-security/2015/05/13/9
  13. http://www.openwall.com/lists/oss-security/2015/05/22/10
  14. http://www.securityfocus.com/bid/74674
  15. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=779274
  16. https://bugzilla.redhat.com/show_bug.cgi?id=1218365
  17. https://github.com/kohler/t1utils/blob/master/NEWS
  18. https://github.com/kohler/t1utils/commit/6b9d1aafcb61a3663c883663eb19ccdbfcde8d33
  19. https://github.com/kohler/t1utils/issues/4
  20. https://security.gentoo.org/glsa/201507-10