MGASA-2015-0367
Dashboard / Vulnerabilities / MGASA-2015-0367
MGASA-2015-0367
Summary: Updated freetype2 packages fix security vulnerabilities
Details: Updated freetype2 packages fix security vulnerabilities: It was discovered that FreeType did not correctly handle certain malformed font files. If a user were tricked into using a specially crafted font file, a remote attacker could cause FreeType to crash or hang, resulting in a denial of service, or possibly expose uninitialized memory (Savannah bugs 41309 and 41590).
References: https://advisories.mageia.org/MGASA-2015-0367.html, https://bugs.mageia.org/show_bug.cgi?id=16739, http://www.ubuntu.com/usn/usn-2739-1/, https://savannah.nongnu.org/bugs/?41309, https://savannah.nongnu.org/bugs/index.php?41590, http://openwall.com/lists/oss-security/2015/09/11/4
Affected packages
Package
Name: freetype2
Purl: pkg:rpm/mageia/freetype2?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
