[Bug 684952] Re: Stack buffer overflow in BDF file parsing

2 views
Skip to first unread message

Louis Simard

unread,
Dec 3, 2010, 4:34:28 PM12/3/10
to ubunt...@lists.ubuntu.com
Attached is a unified format patch which should copy strings correctly within
their allocated buffers, for many fields in the BDF file format, including
CHARSET_REGISTRY.

I have tested FontForge before and after the patch; it does not crash
predictably anymore.

** Patch added: "fix for CVE-2010-4259 crash"
https://bugs.launchpad.net/ubuntu/+source/fontforge/+bug/684952/+attachment/1754634/+files/cve-2010-4259.patch

** Visibility changed to: Public

--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/684952

Title:
Stack buffer overflow in BDF file parsing

--
ubuntu-bugs mailing list
ubunt...@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Louis Simard

unread,
Dec 3, 2010, 4:45:17 PM12/3/10
to ubunt...@lists.ubuntu.com
** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2010-4259

Louis Simard

unread,
Dec 3, 2010, 4:50:22 PM12/3/10
to ubunt...@lists.ubuntu.com
FontForge in Natty, Maverick and Lucid are affected by this
vulnerability.

Since the package is compiled with stack smashing detection enabled, it
may not be exploitable for arbitrary code execution via this
vulnerability.

Kees Cook

unread,
Dec 3, 2010, 6:32:26 PM12/3/10
to ubunt...@lists.ubuntu.com
** This bug is no longer flagged as a security vulnerability

** This bug has been flagged as a security vulnerability

Brian Murray

unread,
Dec 4, 2010, 12:35:10 PM12/4/10
to ubuntu-pat...@lists.ubuntu.com
** Tags added: patch

--
You received this bug notification because you are a member of Ubuntu

Review Team, which is a direct subscriber.
https://bugs.launchpad.net/bugs/684952

Title:
Stack buffer overflow in BDF file parsing

--
Ubuntu-patch-reviews mailing list
Ubuntu-pat...@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-patch-reviews

Marc Deslauriers

unread,
Dec 10, 2010, 10:54:37 AM12/10/10
to ubunt...@lists.ubuntu.com
** Changed in: fontforge (Ubuntu)
Status: New => Confirmed

** Changed in: fontforge (Ubuntu)
Importance: Undecided => Low

--
You received this bug notification because you are a member of Ubuntu

Bugs, which is subscribed to Ubuntu.

https://bugs.launchpad.net/bugs/684952

Title:
Stack buffer overflow in BDF file parsing

--

Reply all
Reply to author
Forward
0 new messages