Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 8 MGASA-2022-0184 Critical: FreeType2 Heap Overflow Issues

mageia
Calendar Grey May 15, 2022
Dist Mageia Esm H88
Recent updates to freetype2 in Mageia tackle several security vulnerabilities, including risks associated with heap overflows and segmentation faults.
FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face

Summary

FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face. (CVE-2022-27404)
FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request. (CVE-2022-27405)
FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the function FT_Request_Size. (CVE-2022-27406)

References

- https://bugs.mageia.org/show_bug.cgi?id=30395

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/FDU2FOEMCEF6WVR6ZBIH5MT5O7FAK6UP/

- https://www.cve.org/CVERecord?id=CVE-2022-27404

- https://www.cve.org/CVERecord?id=CVE-2022-27405

- https://www.cve.org/CVERecord?id=CVE-2022-27406

Resolution

SRPMS

- 8/tainted/freetype2-2.10.4-2.1.mga8.tainted

- 8/core/freetype2-2.10.4-2.1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 15 May 2022
URL: https://advisories.mageia.org/MGASA-2022-0184.html
Type: security
CVE: CVE-2022-27404, CVE-2022-27405, CVE-2022-27406

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here