MGASA-2017-0217
Dashboard / Vulnerabilities / MGASA-2017-0217
MGASA-2017-0217
Summary: Updated graphite2 packages fix security vulnerabilities
Details: An out-of-bounds write triggered with a maliciously crafted Graphite font could lead to a crash or potentially code execution (CVE-2017-5436). Multiple vulnerabilities have been found in the Graphite font rendering engine which might result in denial of service or the execution of arbitrary code if a malformed font file is processed (CVE-2017-7771, CVE-2017-7772, CVE-2017-7773, CVE-2017-7774, CVE-2017-7775, CVE-2017-7776, CVE-2017-7777, CVE-2017-7778).
References: https://advisories.mageia.org/MGASA-2017-0217.html, https://bugs.mageia.org/show_bug.cgi?id=20778, https://lists.opensuse.org/opensuse-updates/2017-05/msg00053.html, https://www.debian.org/security/2017/dsa-3894
Affected packages
Package
Name: graphite2
Purl: pkg:rpm/mageia/graphite2?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
