|
|
Log in / Subscribe / Register

Mageia alert MGASA-2025-0099 (freetype2)

From:  Mageia Updates <updates-announce@ml.mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2025-0099: Updated freetype2 packages fix security vulnerability
Date:  Sun, 16 Mar 2025 06:09:49 +0100
Message-ID:  <20250316050949.9E333A0D2D@duvel.mageia.org>
Archive-link:  Article

MGASA-2025-0099 - Updated freetype2 packages fix security vulnerability Publication date: 16 Mar 2025 URL: https://advisories.mageia.org/MGASA-2025-0099.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-27363 Description: An out of bounds write exists in FreeType versions 2.13.0 and below when attempting to parse font subglyph structures related to TrueType GX and variable font files which may result in arbitrary code execution. References: - https://bugs.mageia.org/show_bug.cgi?id=34095 - https://www.openwall.com/lists/oss-security/2025/03/13/1 - https://gitlab.freedesktop.org/freetype/freetype/-/issues... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-2... SRPMS: - 9/core/freetype2-2.13.0-1.2.mga9 - 9/tainted/freetype2-2.13.0-1.2.mga9.tainted


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds