Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Debian: DSA-2351-1 Important: Libxml2 Integer Overflow Vulnerability

debian
Calendar Grey November 20, 2011
Scroller Debian
A critical security patch for Freetype addresses unchecked input validation that could allow arbitrary code execution. Users are advised to upgrade to ensure system safety.
It was discovered that missing input sanitising in Freetype's processing of CID-keyed fonts could lead to the execution of arbitrary code

Summary

It was discovered that missing input sanitising in Freetype's processing
of CID-keyed fonts could lead to the execution of arbitrary code.

For the oldstable distribution (lenny), this problem has been fixed in
version 2.3.7-2+lenny8.

For the stable distribution (squeeze), this problem has been fixed in
version 2.4.2-2.1+squeeze3.

For the unstable distribution (sid), this problem has been fixed in
version 2.4.8-1.

We recommend that you upgrade your freetype packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: freetype
CVE ID: CVE-2011-3439

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.