Vulnerability Name: CVE-2009-2468 (CCN-51905) Assigned: 2009-07-21 Published: 2009-07-21 Updated: 2009-09-16 Summary: Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4.11 and 10.5.8, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long text run that triggers a heap-based buffer overflow during font glyph rendering, a related issue to CVE-2009-1194 . CVSS v3 Severity: 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C )7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
9.3 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C )6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
Vulnerability Type: CWE-189 Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2009-2468 Source: APPLE Type: UNKNOWNAPPLE-SA-2009-08-11-1 Source: APPLE Type: UNKNOWNAPPLE-SA-2009-09-10-2 Source: CCN Type: SA35914Mozilla Firefox Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory35914 Source: CCN Type: SA36701Apple Mac OS X Security Update Fixes Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN36701 Source: CCN Type: SECTRACK ID: 1022717Apple Safari Buffer Overflows Let Remote Users Execute Arbitrary Code Source: SUNALERT Type: UNKNOWN264308 Source: CCN Type: Apple Web siteAbout the security content of Safari 4.0.3 Source: CONFIRM Type: UNKNOWNhttp://support.apple.com/kb/HT3733 Source: CONFIRM Type: UNKNOWNhttp://support.apple.com/kb/HT3865 Source: CCN Type: MFSA 2009-36Heap/integer overflows in font glyph rendering libraries Source: CONFIRM Type: Vendor Advisoryhttp://www.mozilla.org/security/announce/2009/mfsa2009-36.html Source: BID Type: UNKNOWN35758 Source: CCN Type: BID-35758RETIRED: Mozilla Firefox MFSA 2009-34, -35, -36, -37, -39, -40 Multiple Vulnerabilities Source: CCN Type: BID-35774CoreGraphics Font Glyph Rendering Library Remote Code Execution Vulnerability Source: SECTRACK Type: UNKNOWN1022717 Source: VUPEN Type: Vendor AdvisoryADV-2009-1972 Source: CONFIRM Type: UNKNOWNhttps://bugzilla.mozilla.org/show_bug.cgi?id=480134 Source: XF Type: UNKNOWNfirefox-font-glyph-bo(51905) Vulnerable Configuration: Configuration 1 :cpe:/a:mozilla:firefox:0.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:0.2:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:0.3:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:0.4:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:0.5:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:0.6:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:0.6.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:0.7:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:0.7.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:0.8:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:0.9:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:0.9:rc:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:0.9.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:0.9.2:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:0.9.3:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:0.9_rc:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:0.10:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:0.10.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.0:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.0:preview_release:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.0.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.0.2:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.0.3:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.0.4:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.0.5:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.0.6:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.0.6:*:linux:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.0.7:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.0.8:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.4.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5:beta1:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5:beta2:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5.0.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5.0.2:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5.0.3:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5.0.4:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5.0.5:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5.0.6:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5.0.7:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5.0.8:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5.0.9:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5.0.10:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5.0.11:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5.0.12:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5.2:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5.3:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5.4:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5.5:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5.6:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5.7:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.5.8:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:1.8:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0:beta1:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0:beta_1:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0:rc2:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0:rc3:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.2:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.3:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.4:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.5:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.6:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.7:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.8:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.9:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.10:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.11:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.12:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.13:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.14:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.15:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.16:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.17:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.18:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.19:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.20:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:2.0.0.21:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0:alpha:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0:beta2:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0:beta5:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0.2:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0.3:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0.4:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0.5:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0.6:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0.7:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0.8:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0.9:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0.10:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:*:*:*:*:*:*:*:* (Version <= 3.0.11) Configuration CCN 1 :cpe:/a:mozilla:firefox:3.0:alpha:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0:beta5:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0:beta2:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0.1:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0.3:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0.2:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0.4:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0.5:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.5.6:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0.6:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0.7:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0.8:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0.9:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.0.10:*:*:*:*:*:*:* OR cpe:/a:mozilla:firefox:3.5:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.5.8:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.8:*:*:*:*:*:*:* AND cpe:/a:apple:safari:3.0.1:*:*:*:*:*:*:* OR cpe:/a:apple:safari:3.0.2:*:*:*:*:*:*:* OR cpe:/a:apple:safari:3.0.3:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.5:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5:*:*:*:*:*:*:* OR cpe:/a:apple:safari:3.0.4_beta:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.1:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:* OR cpe:/a:apple:safari:3.1:*:*:*:*:*:*:* OR cpe:/a:apple:safari:3.0:*:*:*:*:*:*:* OR cpe:/a:apple:safari:3.0.4:*:*:*:*:*:*:* OR cpe:/a:apple:safari:3.1.1:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.3:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.5.3:*:*:*:*:*:*:* OR cpe:/a:apple:safari:3.1.2:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.5.4:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.4:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.5.5:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.5:*:*:*:*:*:*:* OR cpe:/o:mandriva:linux:2009.0:*:*:*:*:*:*:* OR cpe:/o:mandriva:linux:2009.0:-:x86_64:*:*:*:*:* OR cpe:/a:apple:safari:3.2:*:*:*:*:*:*:* OR cpe:/a:apple:safari:3.2.1:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.6:*:*:*:*:*:*:* OR cpe:/a:apple:safari:3.2.2:*:*:*:*:*:*:* OR cpe:/a:apple:safari:3.0.0b:*:*:*:*:*:*:* OR cpe:/a:apple:safari:3.0.1b:*:*:*:*:*:*:* OR cpe:/a:apple:safari:3.0.2b:*:*:*:*:*:*:* OR cpe:/a:apple:safari:3.0.3b:*:*:*:*:*:*:* OR cpe:/a:apple:safari:3.1.0:*:*:*:*:*:*:* OR cpe:/a:apple:safari:3.1.0b:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.5.0:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.0:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x:10.5.7:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.7:*:*:*:*:*:*:* OR cpe:/a:apple:safari:3.2.3:*:*:*:*:*:*:* OR cpe:/a:apple:safari:4.0:*:*:*:*:*:*:* OR cpe:/a:apple:safari:4.0.1:*:*:*:*:*:*:* OR cpe:/o:mandriva:linux:2009.1:*:*:*:*:*:*:* OR cpe:/o:mandriva:linux:2009.1:*:*:*:x86_64:*:*:* OR cpe:/o:apple:mac_os_x:10.5.2:2008-002:*:*:*:*:*:* OR cpe:/a:apple:safari:4.0.2:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
mozilla firefox 0.1
mozilla firefox 0.2
mozilla firefox 0.3
mozilla firefox 0.4
mozilla firefox 0.5
mozilla firefox 0.6
mozilla firefox 0.6.1
mozilla firefox 0.7
mozilla firefox 0.7.1
mozilla firefox 0.8
mozilla firefox 0.9
mozilla firefox 0.9 rc
mozilla firefox 0.9.1
mozilla firefox 0.9.2
mozilla firefox 0.9.3
mozilla firefox 0.9_rc
mozilla firefox 0.10
mozilla firefox 0.10.1
mozilla firefox 1.0
mozilla firefox 1.0 preview_release
mozilla firefox 1.0.1
mozilla firefox 1.0.2
mozilla firefox 1.0.3
mozilla firefox 1.0.4
mozilla firefox 1.0.5
mozilla firefox 1.0.6
mozilla firefox 1.0.6
mozilla firefox 1.0.7
mozilla firefox 1.0.8
mozilla firefox 1.4.1
mozilla firefox 1.5
mozilla firefox 1.5 beta1
mozilla firefox 1.5 beta2
mozilla firefox 1.5.0.1
mozilla firefox 1.5.0.2
mozilla firefox 1.5.0.3
mozilla firefox 1.5.0.4
mozilla firefox 1.5.0.5
mozilla firefox 1.5.0.6
mozilla firefox 1.5.0.7
mozilla firefox 1.5.0.8
mozilla firefox 1.5.0.9
mozilla firefox 1.5.0.10
mozilla firefox 1.5.0.11
mozilla firefox 1.5.0.12
mozilla firefox 1.5.1
mozilla firefox 1.5.2
mozilla firefox 1.5.3
mozilla firefox 1.5.4
mozilla firefox 1.5.5
mozilla firefox 1.5.6
mozilla firefox 1.5.7
mozilla firefox 1.5.8
mozilla firefox 1.8
mozilla firefox 2.0
mozilla firefox 2.0 beta1
mozilla firefox 2.0 beta_1
mozilla firefox 2.0 rc2
mozilla firefox 2.0 rc3
mozilla firefox 2.0.0.1
mozilla firefox 2.0.0.2
mozilla firefox 2.0.0.3
mozilla firefox 2.0.0.4
mozilla firefox 2.0.0.5
mozilla firefox 2.0.0.6
mozilla firefox 2.0.0.7
mozilla firefox 2.0.0.8
mozilla firefox 2.0.0.9
mozilla firefox 2.0.0.10
mozilla firefox 2.0.0.11
mozilla firefox 2.0.0.12
mozilla firefox 2.0.0.13
mozilla firefox 2.0.0.14
mozilla firefox 2.0.0.15
mozilla firefox 2.0.0.16
mozilla firefox 2.0.0.17
mozilla firefox 2.0.0.18
mozilla firefox 2.0.0.19
mozilla firefox 2.0.0.20
mozilla firefox 2.0.0.21
mozilla firefox 3.0
mozilla firefox 3.0 alpha
mozilla firefox 3.0 beta2
mozilla firefox 3.0 beta5
mozilla firefox 3.0.1
mozilla firefox 3.0.2
mozilla firefox 3.0.3
mozilla firefox 3.0.4
mozilla firefox 3.0.5
mozilla firefox 3.0.6
mozilla firefox 3.0.7
mozilla firefox 3.0.8
mozilla firefox 3.0.9
mozilla firefox 3.0.10
mozilla firefox *
mozilla firefox 3.0 alpha
apple mac os x 10.4.11
apple mac os x server 10.4.11
mozilla firefox 3.0 beta5
mozilla firefox 3.0 beta2
mozilla firefox 3.0
mozilla firefox 3.0.1
mozilla firefox 3.0.3
mozilla firefox 3.0.2
mozilla firefox 3.0.4
mozilla firefox 3.0.5
apple mac os x 10.5.6
mozilla firefox 3.0.6
mozilla firefox 3.0.7
mozilla firefox 3.0.8
mozilla firefox 3.0.9
mozilla firefox 3.0.10
mozilla firefox 3.5
apple mac os x 10.5.8
apple mac os x server 10.5.8
apple safari 3.0.1
apple safari 3.0.2
apple safari 3.0.3
apple mac os x 10.5
apple mac os x server 10.5
apple safari 3.0.4_beta
apple mac os x 10.5.1
apple mac os x server 10.5.1
apple mac os x 10.5.2
apple mac os x server 10.5.2
apple safari 3.1
apple safari 3.0
apple safari 3.0.4
apple safari 3.1.1
apple mac os x server 10.5.3
apple mac os x 10.5.3
apple safari 3.1.2
apple mac os x 10.5.4
apple mac os x server 10.5.4
apple mac os x 10.5.5
apple mac os x server 10.5.5
mandriva linux 2009.0
mandriva linux 2009.0 -
apple safari 3.2
apple safari 3.2.1
apple mac os x server 10.5.6
apple safari 3.2.2
apple safari 3.0.0b
apple safari 3.0.1b
apple safari 3.0.2b
apple safari 3.0.3b
apple safari 3.1.0
apple safari 3.1.0b
apple mac os x 10.5.0
apple mac os x server 10.5.0
apple mac os x 10.5.7
apple mac os x server 10.5.7
apple safari 3.2.3
apple safari 4.0
apple safari 4.0.1
mandriva linux 2009.1
mandriva linux 2009.1
apple mac os x 10.5.2 2008-002
apple safari 4.0.2