ALT-PU-2017-2190-1
Package libfreetype updated to version 2.8-alt1 for branch sisyphus in task 188122.
Closed vulnerabilities
BDU:2017-00884
Уязвимость библиотеки FreeType, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие
BDU:2017-01282
Уязвимость функции t1_decoder_parse_charstrings библиотеки FreeType, позволяющая нарушителю выполнить запись данных за границами буфера
Modified: 2024-11-21
CVE-2016-10244
The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file.
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/tree/ChangeLog?h=VER-2-7
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/tree/ChangeLog?h=VER-2-7
- DSA-3839
- DSA-3839
- 97405
- 97405
- 1038090
- 1038090
- 1038201
- 1038201
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=36
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=36
- GLSA-201706-14
- GLSA-201706-14
- https://source.android.com/security/bulletin/2017-04-01
- https://source.android.com/security/bulletin/2017-04-01
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpuapr2020.html
Modified: 2024-11-21
CVE-2016-10328
FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c.
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=beecf80a6deecbaf5d264d4f864451bde4fe98b8
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=beecf80a6deecbaf5d264d4f864451bde4fe98b8
- http://savannah.nongnu.org/bugs/?func=detailitem&item_id=49858
- http://savannah.nongnu.org/bugs/?func=detailitem&item_id=49858
- 97677
- 97677
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=289
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=289
- GLSA-201706-14
- GLSA-201706-14
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpuapr2020.html
Modified: 2024-11-21
CVE-2017-7857
FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=7bbb91fbf47fc0775cc9705673caf0c47a81f94b
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=7bbb91fbf47fc0775cc9705673caf0c47a81f94b
- 97680
- 97680
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=759
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=759
- GLSA-201706-14
- GLSA-201706-14
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpuapr2020.html
Modified: 2024-11-21
CVE-2017-7858
FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=779309744222a736eba0f1731e8162fce6288d4e
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=779309744222a736eba0f1731e8162fce6288d4e
- 97682
- 97682
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=738
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=738
- GLSA-201706-14
- GLSA-201706-14
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpuapr2020.html
Modified: 2024-11-21
CVE-2017-7864
FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in truetype/ttobjs.c.
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=e6699596af5c5d6f0ae0ea06e19df87dce088df8
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=e6699596af5c5d6f0ae0ea06e19df87dce088df8
- 97673
- 97673
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=509
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=509
- GLSA-201706-14
- GLSA-201706-14
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpuapr2020.html
Modified: 2024-11-21
CVE-2017-8105
FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=f958c48ee431bef8d4d466b40c9cb2d4dbcb7791
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=f958c48ee431bef8d4d466b40c9cb2d4dbcb7791
- DSA-3839
- DSA-3839
- 99093
- 99093
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=935
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=935
- GLSA-201706-14
- GLSA-201706-14
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
Modified: 2024-11-21
CVE-2017-8287
FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in psaux/psobjs.c.
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=3774fc08b502c3e685afca098b6e8a195aded6a0
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=3774fc08b502c3e685afca098b6e8a195aded6a0
- DSA-3839
- DSA-3839
- 99091
- 99091
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=941
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=941
- GLSA-201706-14
- GLSA-201706-14
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html