Paketname
freetype2
Datum
2010-08-22
Advisory ID
MDVSA-2010:156
Betroffene Versionen
2009.0 x86_64 , MES5 i586 , 2009.1 i586 , 2009.0 i586 , CS4.0 i586 , 2008.0 x86_64 , CS4.0 x86_64 , 2008.0 i586 , 2009.1 x86_64 , MES5 x86_64

Problembeschreibung

Multiple vulnerabilities has been found and corrected in freetype2:

The FT_Stream_EnterFrame function in base/ftstream.c in FreeType
before 2.4.2 does not properly validate certain position values, which
allows remote attackers to cause a denial of service (application
crash) or possibly execute arbitrary code via a crafted font file
(CVE-2010-2805).

Array index error in the t42_parse_sfnts function in type42/t42parse.c
in FreeType before 2.4.2 allows remote attackers to cause a denial of
service (application crash) or possibly execute arbitrary code via
negative size values for certain strings in FontType42 font files,
leading to a heap-based buffer overflow (CVE-2010-2806).

FreeType before 2.4.2 uses incorrect integer data types during bounds
checking, which allows remote attackers to cause a denial of service
(application crash) or possibly execute arbitrary code via a crafted
font file (CVE-2010-2807).

Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c
in FreeType before 2.4.2 allows remote attackers to cause a denial of
service (memory corruption and application crash) or possibly execute
arbitrary code via a crafted Adobe Type 1 Mac Font File (aka LWFN)
font (CVE-2010-2808).

bdf/bdflib.c in FreeType before 2.4.2 allows remote attackers to cause
a denial of service (application crash) via a crafted BDF font file,
related to an attempted modification of a value in a static string
(CVE-2010-3053).

Unspecified vulnerability in FreeType 2.3.9, and other versions
before 2.4.2, allows remote attackers to cause a denial of service
via vectors involving nested Standard Encoding Accented Character
(aka seac) calls, related to psaux.h, cffgload.c, cffgload.h, and
t1decode.c (CVE-2010-3054).

Packages for 2008.0 and 2009.0 are provided as of the Extended
Maintenance Program. Please visit this link to learn more:
http://store.mandriva.com/product_info.php?cPath=149&products_id=490

The updated packages have been patched to correct these issues.

Aktualisierte Pakete

2009.0 x86_64

 daf8318e7b97d0781fa8403145d09d8b  2009.0/x86_64/lib64freetype6-2.3.7-1.4mdv2009.0.x86_64.rpm
 5cbfff99d66a0133a52a438a7aaeea20  2009.0/x86_64/lib64freetype6-devel-2.3.7-1.4mdv2009.0.x86_64.rpm
 8aa86b0aba83c69d7ea2f6cef14ea420  2009.0/x86_64/lib64freetype6-static-devel-2.3.7-1.4mdv2009.0.x86_64.rpm 
 45197fd09ebbc0dd4b7f704843568d7a  2009.0/SRPMS/freetype2-2.3.7-1.4mdv2009.0.src.rpm

MES5 i586

 12cda3818dde1eaeb0fecc8f280e69ab  mes5/i586/libfreetype6-2.3.7-1.4mdvmes5.1.i586.rpm
 8906db2649c57e95df267bea2f966e62  mes5/i586/libfreetype6-devel-2.3.7-1.4mdvmes5.1.i586.rpm
 03d24b33e39931fac9ee87f2da4bd102  mes5/i586/libfreetype6-static-devel-2.3.7-1.4mdvmes5.1.i586.rpm 
 4144b8e7112835012774ceff3a4465b0  mes5/SRPMS/freetype2-2.3.7-1.4mdvmes5.1.src.rpm

2009.1 i586

 d5a7a6e2f6ed6b27be3b4c65cf8db53f  2009.1/i586/libfreetype6-2.3.9-1.5mdv2009.1.i586.rpm
 40a0a8d44bfe4ec11f3e997ed9edb223  2009.1/i586/libfreetype6-devel-2.3.9-1.5mdv2009.1.i586.rpm
 02597999b4a298ab1ab3d899c56e3931  2009.1/i586/libfreetype6-static-devel-2.3.9-1.5mdv2009.1.i586.rpm 
 3b53c61c4f842c7430efb0ba8635780e  2009.1/SRPMS/freetype2-2.3.9-1.5mdv2009.1.src.rpm

2009.0 i586

 9c93eb065e0fb99af3c7f8e23d323ff6  2009.0/i586/libfreetype6-2.3.7-1.4mdv2009.0.i586.rpm
 9d18899bdac168770c4d44b1e1610107  2009.0/i586/libfreetype6-devel-2.3.7-1.4mdv2009.0.i586.rpm
 1865120e616ce57a9d8a3a91980456d3  2009.0/i586/libfreetype6-static-devel-2.3.7-1.4mdv2009.0.i586.rpm 
 45197fd09ebbc0dd4b7f704843568d7a  2009.0/SRPMS/freetype2-2.3.7-1.4mdv2009.0.src.rpm

CS4.0 i586

 e65d074d40c5674d71645c0b953fa72c  corporate/4.0/i586/libfreetype6-2.1.10-9.12.20060mlcs4.i586.rpm
 6d079e702800250eb1fdc29e3b6671b9  corporate/4.0/i586/libfreetype6-devel-2.1.10-9.12.20060mlcs4.i586.rpm
 ad17cec3f86861c64df161cde9f878d2  corporate/4.0/i586/libfreetype6-static-devel-2.1.10-9.12.20060mlcs4.i586.rpm 
 49d536d05fbb579529052c3fe8f5bb70  corporate/4.0/SRPMS/freetype2-2.1.10-9.12.20060mlcs4.src.rpm

2008.0 x86_64

 537b00290a2d20e10bfd103a01bfbcbe  2008.0/x86_64/lib64freetype6-2.3.5-2.5mdv2008.0.x86_64.rpm
 28178fd2d4c12cb0806f29a283b56e60  2008.0/x86_64/lib64freetype6-devel-2.3.5-2.5mdv2008.0.x86_64.rpm
 fccebfb3e2bc0f752ef37700107db924  2008.0/x86_64/lib64freetype6-static-devel-2.3.5-2.5mdv2008.0.x86_64.rpm 
 d56c81e34ba5a646112cf7f54d1b6770  2008.0/SRPMS/freetype2-2.3.5-2.5mdv2008.0.src.rpm

CS4.0 x86_64

 a8a1aa31b5dbae30a8a40c18d0f9aa0f  corporate/4.0/x86_64/lib64freetype6-2.1.10-9.12.20060mlcs4.x86_64.rpm
 a9070117f5ea61b8da081ab5ffcf0e8d  corporate/4.0/x86_64/lib64freetype6-devel-2.1.10-9.12.20060mlcs4.x86_64.rpm
 225ae55631ecd27e702a3dc032d958d9  corporate/4.0/x86_64/lib64freetype6-static-devel-2.1.10-9.12.20060mlcs4.x86_64.rpm 
 49d536d05fbb579529052c3fe8f5bb70  corporate/4.0/SRPMS/freetype2-2.1.10-9.12.20060mlcs4.src.rpm

2008.0 i586

 b8ab28fadc221eeae0ea9d9d14648be6  2008.0/i586/libfreetype6-2.3.5-2.5mdv2008.0.i586.rpm
 b1341c5c0f0ed584ce12b5076af1bfa0  2008.0/i586/libfreetype6-devel-2.3.5-2.5mdv2008.0.i586.rpm
 b806a4715130d102ea43695fe943cadf  2008.0/i586/libfreetype6-static-devel-2.3.5-2.5mdv2008.0.i586.rpm 
 d56c81e34ba5a646112cf7f54d1b6770  2008.0/SRPMS/freetype2-2.3.5-2.5mdv2008.0.src.rpm

2009.1 x86_64

 68cb77ee3e1a6f154893976f9f2c86f5  2009.1/x86_64/lib64freetype6-2.3.9-1.5mdv2009.1.x86_64.rpm
 52079b7f8a02a8a82eb74dd3dd7f1ac2  2009.1/x86_64/lib64freetype6-devel-2.3.9-1.5mdv2009.1.x86_64.rpm
 3ae9c45414c50fe341c2b65ed2589128  2009.1/x86_64/lib64freetype6-static-devel-2.3.9-1.5mdv2009.1.x86_64.rpm 
 3b53c61c4f842c7430efb0ba8635780e  2009.1/SRPMS/freetype2-2.3.9-1.5mdv2009.1.src.rpm

MES5 x86_64

 aa4547c5192dbafe9fa713e8c555f995  mes5/x86_64/lib64freetype6-2.3.7-1.4mdvmes5.1.x86_64.rpm
 eaed945ee28b755846369e3ee4961a87  mes5/x86_64/lib64freetype6-devel-2.3.7-1.4mdvmes5.1.x86_64.rpm
 eb183880095fdf063c2e96b15ab7b613  mes5/x86_64/lib64freetype6-static-devel-2.3.7-1.4mdvmes5.1.x86_64.rpm 
 4144b8e7112835012774ceff3a4465b0  mes5/SRPMS/freetype2-2.3.7-1.4mdvmes5.1.src.rpm

Referenzen