Denial of Service in Freetype
ID: | USN-3572-1 |
Distribution: | Ubuntu |
Plattformen: | Ubuntu 17.10 |
Datum: | Do, 15. Februar 2018, 00:12 |
Referenzen: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6942 |
Applikationen: | Freetype |
Originalnachricht |
|
--===============5797927329081628574== Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="=-aBGRd/VByB9PbZoyDN2m" --=-aBGRd/VByB9PbZoyDN2m Content-Type: text/plain; charset="UTF-8 Content-Transfer-Encoding: quoted-printable ========================================================================== Ubuntu Security Notice USN-3572-1 February 14, 2018 freetype vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 17.10 Summary: FreeType could be made to crash if it opened a specially crafted file. Software Description: - freetype: FreeType 2 is a font engine library Details: It was discovered that FreeType incorrectly handled certain files. An attacker could possibly use this to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 17.10: libfreetype6 2.8-0.2ubuntu2.1 After a standard system update you need to restart your session to make all the necessary changes. References: https://www.ubuntu.com/usn/usn-3572-1 CVE-2018-6942 Package Information: https://launchpad.net/ubuntu/+source/freetype/2.8-0.2ubuntu2.1 --=-aBGRd/VByB9PbZoyDN2m Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part Content-Transfer-Encoding: 7bit -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAABCAAGBQJahI0QAAoJEEW851uECx9pyA8P/2POfgKTYoEQBp+Z9ta0s03k gwnv7zR/Ewb/ftFhZwvd3z4NNgfVFABHtAysG0xcTZpkOdphUXZX0LYiFfhQDc8q 3lv+47CuPkQcxmIzVNgWN/oo3fA77+rseR6pjnMxOq2FnojgqQRJg47tlXN6LH+M KAiccMIK6GtlLXEsb/xCQZ3eYK4c+XydxuwZyiRZ3hRgRAzvuW1P+u2o+VizvWi9 eUt74lDHJeNl3L4IE2aix4DOaGHphUzZXjlr9Fwt1eKaSUEQftnVfj+DhBPIEvyJ bu8AQQ1IoCJgatVjqosUBBECSRXT4wbg4gHpp5RGHTCYD6q1FwSg56Fh/8+6mn89 NfNIBW0ykHHRGxVk5JKSjGDxz+V2lDkJ1Ir8lHzEIeyXo1+QjiLWM0LFzNx0RmRC l+4aVIjgS+PslMO/J7cT7IsXe0CetuDuexFnRyzFLUs4NyTLOmPbYUXPPSBjTwX4 0BMEYRMOE+RBytvJQ2fX6rvJKHLvzN2dvL96ku3AGBej2Vc+GxkoF5wyjwDmziXc px/vElUqWo03vnlAUMteNmDQMwTxk/EguRPWVqSKTB35SSav83TAlX7MOZ5Mqgu6 qwVY2Iw0hTUU7MjrLU3C0vkqKugSDbbOz8+TTHjnjG2aQTjzuifNdSV5HGBb+4bj 3dgAlKLRwtssxwxwI6eW =M6Hp -----END PGP SIGNATURE----- --=-aBGRd/VByB9PbZoyDN2m-- --===============5797927329081628574== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5 LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj dXJpdHktYW5ub3VuY2UK --===============5797927329081628574==-- |