Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
FreeType could be made to crash or run programs as your login if it opened a
specially crafted font file.
Software Description:
- freetype: FreeType 2 is a font engine library
Details:
Mateusz Jurczyk discovered that FreeType did not correctly handle certain
malformed BDF font files. If a user were tricked into using a specially crafted
font file, a remote attacker could cause FreeType to crash. (CVE-2012-1126)
Mateusz Jurczyk discovered that FreeType did not correctly handle certain
malformed BDF font files. If a user were tricked into using a specially crafted
font file, a remote attacker could cause FreeType to crash. (CVE-2012-1127)
Mateusz Jurczyk discovered that FreeType did not correctly handle certain
malformed TrueType font files. If a user were tricked into using a specially
crafted font file, a remote attacker could cause FreeType to crash.
(CVE-2012-1128)
Mateusz Jurczyk discovered that FreeType did not correctly handle certain
malformed Type42 font files. If a us...
The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: libfreetype6 2.4.4-2ubuntu1.2 Ubuntu 11.04: libfreetype6 2.4.4-1ubuntu2.3 Ubuntu 10.10: libfreetype6 2.4.2-2ubuntu0.4 Ubuntu 10.04 LTS: libfreetype6 2.3.11-1ubuntu2.6 Ubuntu 8.04 LTS: libfreetype6 2.3.5-1ubuntu4.8.04.9 After a standard system update you need to restart your session to make all the necessary changes.
https://ubuntu.com/security/notices/USN-1403-1
CVE-2012-1126, CVE-2012-1127, CVE-2012-1128, CVE-2012-1129,
CVE-2012-1130, CVE-2012-1131, CVE-2012-1132, CVE-2012-1133,
CVE-2012-1134, CVE-2012-1135, CVE-2012-1136, CVE-2012-1137,
CVE-2012-1138, CVE-2012-1139, CVE-2012-1140, CVE-2012-1141,
CVE-2012-1142, CVE-2012-1143, CVE-2012-1144
Get the latest Linux and open source security news straight to your inbox.