SCIENTIFIC-LINUX-ERRATA Archives

October 2011

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Tue, 25 Oct 2011 16:09:18 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (69 lines)
Synopsis:    Important: freetype security update
Issue Date:  2011-10-25
CVE Numbers: CVE-2011-3256


FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. The freetype packages for Scientific Linux 4 provide
both the FreeType 1 and FreeType 2 font engines. The freetype packages for
Scientific Linux 5 and 6 provide only the FreeType 2 font engine.

Multiple input validation flaws were found in the way FreeType processed
bitmap font files. If a specially-crafted font file was loaded by an
application linked against FreeType, it could cause the application to
crash or, potentially, execute arbitrary code with the privileges of the
user running the application. (CVE-2011-3256)

Note: These issues only affected the FreeType 2 font engine.

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct these issues. The X server must be restarted
(log out, then log back in) for this update to take effect.

SL4:
  i386
     freetype-2.1.9-20.el4.i386.rpm
     freetype-debuginfo-2.1.9-20.el4.i386.rpm
     freetype-demos-2.1.9-20.el4.i386.rpm
     freetype-devel-2.1.9-20.el4.i386.rpm
     freetype-utils-2.1.9-20.el4.i386.rpm
  x86_64
     freetype-2.1.9-20.el4.i386.rpm
     freetype-2.1.9-20.el4.x86_64.rpm
     freetype-debuginfo-2.1.9-20.el4.i386.rpm
     freetype-debuginfo-2.1.9-20.el4.x86_64.rpm
     freetype-demos-2.1.9-20.el4.x86_64.rpm
     freetype-devel-2.1.9-20.el4.x86_64.rpm
     freetype-utils-2.1.9-20.el4.x86_64.rpm
SL5:
  i386
     freetype-2.2.1-28.el5_7.1.i386.rpm
     freetype-debuginfo-2.2.1-28.el5_7.1.i386.rpm
     freetype-demos-2.2.1-28.el5_7.1.i386.rpm
     freetype-devel-2.2.1-28.el5_7.1.i386.rpm
  x86_64
     freetype-2.2.1-28.el5_7.1.i386.rpm
     freetype-2.2.1-28.el5_7.1.x86_64.rpm
     freetype-debuginfo-2.2.1-28.el5_7.1.i386.rpm
     freetype-debuginfo-2.2.1-28.el5_7.1.x86_64.rpm
     freetype-demos-2.2.1-28.el5_7.1.x86_64.rpm
     freetype-devel-2.2.1-28.el5_7.1.i386.rpm
     freetype-devel-2.2.1-28.el5_7.1.x86_64.rpm
SL6:
  i386
     freetype-2.3.11-6.el6_1.7.i686.rpm
     freetype-debuginfo-2.3.11-6.el6_1.7.i686.rpm
     freetype-demos-2.3.11-6.el6_1.7.i686.rpm
     freetype-devel-2.3.11-6.el6_1.7.i686.rpm
  x86_64
     freetype-2.3.11-6.el6_1.7.i686.rpm
     freetype-2.3.11-6.el6_1.7.x86_64.rpm
     freetype-debuginfo-2.3.11-6.el6_1.7.i686.rpm
     freetype-debuginfo-2.3.11-6.el6_1.7.x86_64.rpm
     freetype-demos-2.3.11-6.el6_1.7.x86_64.rpm
     freetype-devel-2.3.11-6.el6_1.7.i686.rpm
     freetype-devel-2.3.11-6.el6_1.7.x86_64.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2