MGASA-2014-0130
Dashboard / Vulnerabilities / MGASA-2014-0130
Summary: Updated freetype2 packages fix security vulnerabilities
Details: It was reported that Freetype before 2.5.3 suffers from an out-of-bounds stack-based read/write flaw in cf2_hintmap_build() in the CFF rasterizing code, which could lead to a buffer overflow (CVE-2014-2240). It was also reported that Freetype before 2.5.3 has a denial-of-service vulnerability in the CFF rasterizing code, due to a reachable assertion (CVE-2014-2241).
References: https://advisories.mageia.org/MGASA-2014-0130.html, https://bugs.mageia.org/show_bug.cgi?id=12986, https://bugzilla.redhat.com/show_bug.cgi?id=1074646, https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=741299
Affected packages
Package
Name: freetype2
Purl: pkg:rpm/mageia/freetype2?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
