CVE-2012-1135
CVE-2012-1135
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors involving the NPUSHB and NPUSHW instructions in a TrueType font.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00015.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=733512https://bugzilla.redhat.com/show_bug.cgi?id=800593http://secunia.com/advisories/48508http://secunia.com/advisories/48797http://secunia.com/advisories/48822http://secunia.com/advisories/48918http://secunia.com/advisories/48951