Package name
freetype2
Date
2013-02-01
Advisory ID
MDVSA-2013:006
Affected versions
MES5 i586 , 2011 i586 , MES5 x86_64 , 2011 x86_64

Problem description

Multiple vulnerabilities has been found and corrected in freetype2:

A Null pointer de-reference flaw was found in the way Freetype font
rendering engine handled Glyph bitmap distribution format (BDF)
fonts. A remote attacker could provide a specially-crafted BDF font
file, which once processed in an application linked against FreeType
would lead to that application crash (CVE-2012-5668).

An out-of heap-based buffer read flaw was found in the way FreeType
font rendering engine performed parsing of glyph information and
relevant bitmaps for glyph bitmap distribution format (BDF). A remote
attacker could provide a specially-crafted BDF font file, which once
opened in an application linked against FreeType would lead to that
application crash (CVE-2012-5669).

The updated packages have been patched to correct these issues.

Updated packages

MES5 i586

 505e61f7fc629cc51bce2777983da6ef  mes5/i586/freetype2-demos-2.3.7-1.11mdvmes5.2.i586.rpm
 d6472b584d439b2149fa136995e0bd3e  mes5/i586/libfreetype6-2.3.7-1.11mdvmes5.2.i586.rpm
 2cbc0e8ba2697ad6534c8a97b6776448  mes5/i586/libfreetype6-devel-2.3.7-1.11mdvmes5.2.i586.rpm
 a678543b7e22d42a8c5f753c59e30087  mes5/i586/libfreetype6-static-devel-2.3.7-1.11mdvmes5.2.i586.rpm 
 9af34144efab6305f17b8a2e296d91ce  mes5/SRPMS/freetype2-2.3.7-1.11mdvmes5.2.src.rpm

2011 i586

 2f3fec203494eb640bb48614b8cdbb27  2011/i586/freetype2-demos-2.4.5-2.4-mdv2011.0.i586.rpm
 89091b1ba606e039e60303d358947fdc  2011/i586/libfreetype6-2.4.5-2.4-mdv2011.0.i586.rpm
 6c2eae3f6588bc307b4ebb646c1a4c25  2011/i586/libfreetype6-devel-2.4.5-2.4-mdv2011.0.i586.rpm
 bcbd756fd42addea3fd2a38a11567f7a  2011/i586/libfreetype6-static-devel-2.4.5-2.4-mdv2011.0.i586.rpm 
 6c70cd4370fa8ed01c0285c46bba3597  2011/SRPMS/freetype2-2.4.5-2.4.src.rpm

MES5 x86_64

 34ff382889cc95c97f1c68e6c234fd4c  mes5/x86_64/freetype2-demos-2.3.7-1.11mdvmes5.2.x86_64.rpm
 8d736d3cde5ca7348f6a4fff11016eda  mes5/x86_64/lib64freetype6-2.3.7-1.11mdvmes5.2.x86_64.rpm
 abeb5fc6c8a8a36c50147500c412a6fd  mes5/x86_64/lib64freetype6-devel-2.3.7-1.11mdvmes5.2.x86_64.rpm
 4da0078d481d44a06445586dcc9e0e90  mes5/x86_64/lib64freetype6-static-devel-2.3.7-1.11mdvmes5.2.x86_64.rpm 
 9af34144efab6305f17b8a2e296d91ce  mes5/SRPMS/freetype2-2.3.7-1.11mdvmes5.2.src.rpm

2011 x86_64

 abe907ac020e7a6a84d1e0eb86858aa1  2011/x86_64/freetype2-demos-2.4.5-2.4-mdv2011.0.x86_64.rpm
 07c54a3f0face61f8cbb5983759ca9cb  2011/x86_64/lib64freetype6-2.4.5-2.4-mdv2011.0.x86_64.rpm
 73ab4f6bf793c93a387eb7434c834900  2011/x86_64/lib64freetype6-devel-2.4.5-2.4-mdv2011.0.x86_64.rpm
 41c33cc62c33163285ea2c0b1ce44532  2011/x86_64/lib64freetype6-static-devel-2.4.5-2.4-mdv2011.0.x86_64.rpm 
 6c70cd4370fa8ed01c0285c46bba3597  2011/SRPMS/freetype2-2.4.5-2.4.src.rpm

References