USN-3398-1
Dashboard / Vulnerabilities / USN-3398-1
USN-3398-1
Summary: graphite2 vulnerabilities
Details: Holger Fuhrmannek and Tyson Smith discovered that graphite2 incorrectly handled certain malformed fonts. If a user or automated system were tricked into opening a specially-crafted font file, a remote attacker could use this issue to cause graphite2 to crash, resulting in a denial of service, or possibly execute arbitrary code.
References: https://ubuntu.com/security/notices/USN-3398-1, https://ubuntu.com/security/CVE-2017-7771, https://ubuntu.com/security/CVE-2017-7772, https://ubuntu.com/security/CVE-2017-7773, https://ubuntu.com/security/CVE-2017-7774, https://ubuntu.com/security/CVE-2017-7775, https://ubuntu.com/security/CVE-2017-7776, https://ubuntu.com/security/CVE-2017-7777, https://ubuntu.com/security/CVE-2017-7778
Affected packages
Package
Name: graphite2
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
