Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian 7 DLA-918-1 Moderate: Freetype Heap-Based Buffer Overflow Fix

debian lts
Calendar Grey April 26, 2017
Dist Debian Esm H88
Freetype security patch resolves buffer overflow vulnerability and undoes prior CVE remedy. Upgrade strongly advised for users of Debian.
It was found that an out of bounds write caused by a heap-based buffer overflow could be triggered in freetype via a crafted font

Summary

This update also reverts the fix for CVE-2016-10328, as it was
determined that freetype 2.4.9 is not affected by that issue.

For Debian 7 "Wheezy", these problems have been fixed in version
2.4.9-1.1+deb7u6.

We recommend that you upgrade your freetype packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Package: freetype
Version: 2.4.9-1.1+deb7u6
CVE ID: CVE-2017-8105
Debian Bug: 861220 860303

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here