OpenPKG Security Advisory
OpenPKG-SA-2006.017
Publisher Name: OpenPKG GmbH
Publisher Home: http://openpkg.com/
Advisory Id (public): OpenPKG-SA-2006.017
Advisory Type: OpenPKG Security Advisory (SA)
Advisory Directory: http://openpkg.com/go/OpenPKG-SA
Advisory Document: http://openpkg.com/go/OpenPKG-SA-2006.017
Advisory Published: 2010-02-09 17:42 UTC
Issue Id (internal): OpenPKG-SI-20060728.03
Issue First Created: 2006-07-28
Issue Last Modified: 2006-12-07
Issue Revision: 10
Subject Name: Freetype
Subject Summary: TrueType Font (TTF) Rendering Library
Subject Home: http://freetype.sourceforge.net/
Subject Versions: * <= 2.1.10
Vulnerability Id: CVE-2006-3467, CVE-2006-2661, CVE-2006-1861, CVE-2006-0747
Vulnerability Scope: global (not OpenPKG specific)
Attack Feasibility: run-time
Attack Vector: local system
Attack Impact: denial of service, arbitrary code execution
Description:
Multiple security issues exist in the FreeType [1] font rendering
library before version 2.2:
An integer overflow allows remote attackers to cause a Denial of
Service (DoS) and possibly execute arbitrary code via unknown vectors,
as demonstrated by the Red Hat "bad1.pcf" test file, due to a partial
fix of CVE-2006-1861. CVE-2006-3467
Remote attackers can cause a Denial of Service (DoS) via a specially
crafted font file that triggers a NULL dereference. CVE-2006-2661
Multiple integer overflows allow remote attackers to cause a
Denial of Service (DoS) and possibly execute arbitrary code.
CVE-2006-1861. Parts relate to rejected CVE-2006-2493.
Integer underflow allows remote attackers to cause a Denial of Service
(DoS) via a specially crafted font file with an odd number of "blue"
values, which causes the underflow when decrementing by 2 in a context
that assumes an even number of values. CVE-2006-0747
An additional flaw causes some programs to go into an infinite loop
and this way cause a Denial of Service (DoS) when dealing with fonts
that don't have a properly sorted kerning sub-table.
References:
[1] http://www.freetype.org/
Primary Package Name: freetype
Primary Package Home: http://openpkg.org/go/package/freetype
Affected Distribution: Affected Branch: Affected Package:
OpenPKG Community 2.5-SOLID freetype-2.1.10-2.5.0
OpenPKG Community 2-STABLE n/a
OpenPKG Community CURRENT n/a
Corrected Distribution: Corrected Branch: Corrected Package:
OpenPKG Community 2.5-SOLID freetype-2.1.10-2.5.1
OpenPKG Community 2-STABLE n/a
OpenPKG Community CURRENT n/a