LWN.net Logo

freetype: code execution

Package(s):freetype CVE #(s):CVE-2011-3439
Created:November 17, 2011 Updated:April 19, 2012
Description:

From the Red Hat advisory:

Multiple input validation flaws were found in the way FreeType processed CID-keyed fonts. If a specially-crafted font file was loaded by an application linked against FreeType, it could cause the application to crash or, potentially, execute arbitrary code with the privileges of the user running the application. (CVE-2011-3439)

Alerts:
SUSE SUSE-SU-2011:1307-1 2011-12-08
SUSE SUSE-SU-2011:1306-1 2011-12-08
Fedora FEDORA-2011-15964 2011-12-04
Fedora FEDORA-2011-15956 2011-11-15
Fedora FEDORA-2011-15927 2011-11-15
CentOS CESA-2011:1455 2011-11-18
Ubuntu USN-1267-1 2011-11-18
Oracle ELSA-2011-1455 2011-11-17
Oracle ELSA-2011-1455 2011-11-17
Oracle ELSA-2011-1455 2011-11-17
Red Hat RHSA-2011:1455-01 2011-11-16
Mandriva MDVSA-2011:177 2011-11-21
Debian DSA-2350-1 2011-11-20
CentOS CESA-2011:1455 2011-11-18
Scientific Linux SL-free-20111116 2011-11-16
openSUSE openSUSE-SU-2012:0015-1 2012-01-05
Gentoo 201201-09 2012-01-23
Red Hat RHSA-2012:0094-01 2012-02-02
Oracle ELSA-2012-0467 2012-04-12
Fedora FEDORA-2012-4946 2012-04-18
SUSE SUSE-SU-2012:0553-1 2012-04-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds