SCIENTIFIC-LINUX-ERRATA Archives

August 2010

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Connie Sieh <[log in to unmask]>
Reply To:
Connie Sieh <[log in to unmask]>
Date:
Sun, 1 Aug 2010 20:32:52 -0500
Content-Type:
TEXT/PLAIN
Parts/Attachments:
TEXT/PLAIN (49 lines)
Synopsis:          Important: freetype security update
Issue date:        2010-07-30
CVE Names:         CVE-2010-2500 CVE-2010-2527 CVE-2010-2541

FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. These packages provide both the FreeType 1 and FreeType 2 font
engines.

An integer overflow flaw was found in the way the FreeType font engine
processed font files. If a user loaded a carefully-crafted font file with
an application linked against FreeType, it could cause the application to
crash or, possibly, execute arbitrary code with the privileges of the user
running the application. (CVE-2010-2500)

Several buffer overflow flaws were found in the FreeType demo applications.
If a user loaded a carefully-crafted font file with a demo application, it
could cause the application to crash or, possibly, execute arbitrary code
with the privileges of the user running the application. (CVE-2010-2527,
CVE-2010-2541)

We would like to thank Robert Swiecki of the Google Security Team for
the discovery of the CVE-2010-2500 and CVE-2010-2527 issues.

Note: All of the issues in this erratum only affect the FreeType 2 font
engine.

Users are advised to upgrade to these updated packages, which contain
backported patches to correct these issues. The X server must be restarted
(log out, then log back in) for this update to take effect.

SL 3

Source:
   freetype-2.1.4-15.el3.src.rpm

i386:
   freetype-2.1.4-15.el3.i386.rpm
   freetype-devel-2.1.4-15.el3.i386.rpm

x86_64:
   freetype-2.1.4-15.el3.i386.rpm
   freetype-2.1.4-15.el3.x86_64.rpm
   freetype-devel-2.1.4-15.el3.x86_64.rpm


-Connie Sieh
-Troy Dawson

ATOM RSS1 RSS2