Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
[ GLSA 200806-10 ] FreeType: User-assisted execution of arbitrary code
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index News & Announcements
View previous topic :: View next topic  
Author Message
GLSA
Veteran
Veteran


Joined: 12 May 2004
Posts: 1571

PostPosted: Tue Jun 24, 2008 1:26 am    Post subject: [ GLSA 200806-10 ] FreeType: User-assisted execution of arbi Reply with quote

Gentoo Linux Security Advisory

Title: FreeType: User-assisted execution of arbitrary code (GLSA 200806-10)
Severity: normal
Exploitable: remote
Date: June 23, 2008
Updated: May 28, 2009
Bug(s): #225851
ID: 200806-10

Synopsis

Font parsing vulnerabilities in FreeType might lead to user-assisted execution of arbitrary code.

Background

FreeType is a font rendering library for TrueType Font (TTF) and Printer Font Binary (PFB).

Affected Packages

Package: media-libs/freetype
Vulnerable: < 2.3.6
Unaffected: >= 2.3.6
Unaffected: >= 1.4_pre20080316-r1 < 1.5
Architectures: All supported architectures


Description

Regenrecht reported multiple vulnerabilities in FreeType via iDefense:
  • An integer overflow when parsing values in the Private dictionary table in a PFB file, leading to a heap-based buffer overflow (CVE-2008-1806).
  • An invalid free() call related to parsing an invalid "number of axes" field in a PFB file (CVE-2008-1807).
  • Multiple off-by-one errors when parsing PBF and TTF files, leading to heap-based buffer overflows (CVE-2008-1808).


Impact

A remote attacker could entice a user to open a specially crafted TTF or PBF file, possibly resulting in the execution of arbitrary code with the privileges of the user running an application linked against FreeType (such as the X.org X server, running as root).

Workaround

There is no known workaround at this time.

Resolution

All FreeType users should upgrade to the latest version:
Code:
# emerge --sync
# emerge --ask --oneshot --verbose ">=media-libs/freetype-2.3.6"


References

CVE-2008-1806
CVE-2008-1807
CVE-2008-1808


Last edited by GLSA on Fri May 29, 2009 4:18 am; edited 2 times in total
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index News & Announcements All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum