Login
Newsletter
Werbung

Sicherheit: Preisgabe von Informationen in Freetype
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in Freetype
ID: USN-2739-1
Distribution: Ubuntu
Plattformen: Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 15.04
Datum: Do, 10. September 2015, 20:14
Referenzen: Keine Angabe
Applikationen: Freetype

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============2557486553624838212==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="JERHqVLD3e5rQipbETatHofxjpOIFXGvE"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--JERHqVLD3e5rQipbETatHofxjpOIFXGvE
Content-Type: text/plain; charset=utf-
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-2739-1
September 10, 2015

freetype vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in FreeType.

Software Description:
- freetype: FreeType 2 is a font engine library

Details:

It was discovered that FreeType did not correctly handle certain malformed
font files. If a user were tricked into using a specially crafted font
file, a remote attacker could cause FreeType to crash or hang, resulting in
a denial of service, or possibly expose uninitialized memory.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.04:
libfreetype6 2.5.2-2ubuntu3.1

Ubuntu 14.04 LTS:
libfreetype6 2.5.2-1ubuntu2.5

Ubuntu 12.04 LTS:
libfreetype6 2.4.8-1ubuntu2.3

After a standard system update you need to restart your session to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2739-1
https://launchpad.net/bugs/1449225, https://launchpad.net/bugs/1492124

Package Information:
https://launchpad.net/ubuntu/+source/freetype/2.5.2-2ubuntu3.1
https://launchpad.net/ubuntu/+source/freetype/2.5.2-1ubuntu2.5
https://launchpad.net/ubuntu/+source/freetype/2.4.8-1ubuntu2.3



--JERHqVLD3e5rQipbETatHofxjpOIFXGvE
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJV8cEEAAoJEGVp2FWnRL6Tj4gP/1bQeFpy4K2Md1JY1+x4j6Av
FjOYUWixfzD1kKZRz80jDv4bsrR3KDopCrF1jo48BvJRIxLP8qYA5QM98yZg0f0l
hMXoMSLeORx3drnv4dXXD0y0nwuWi1He7Y/ssipmZqi6av2hQjA9s/TSyZXMXAiP
2HHUgvic+LbjTLX5P8bfjogyuFE0K2PswOpW7F3uDnhUJJ/O61F/PwlM6hzMlvIq
G8awXUVkMoBW/Z/r1LIIMMSd2q/kXcDy+ulIm3KN5mWMiwK7zkVos+QThfoVZTYo
ROB4iwShKpMlhtZcicnmhdq9DSuu/w2tf0YgqTPFzcYV8nobG3xDBnLVoyBjoCIq
mNHUIjy4m/1wQEhcJQ2yYC85VRWV0pBPEjNCeBq8Fo6DmIh7Dfwt5nr4s4gt9IlH
ZpXP/Qh4SIQ4SG7SXcRACZmleLjA7alWlgWwoYuh98J6I5LrkAEPPwvXhkYt4Erp
T91axxmNbf2DyCF2OJhG2KdzDJIgCGhT0z7eidsYVwy6BBNIaGmMxpILaQrFIG3r
uuSkgeXR0oo0arNCKzH+oV65Yu9baSaVvbV5t8NVPAn8BcY0nyDvYD3WlQk1PwuZ
bgyM/0Fusg/SoVNL+zl0t1ytnffKKQP7NhTeSRid0gtFyl679wLHeaupevU44yHZ
kPOfijkrTJnCFm4Up1dr
=OIz4
-----END PGP SIGNATURE-----

--JERHqVLD3e5rQipbETatHofxjpOIFXGvE--


--===============2557486553624838212==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============2557486553624838212==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung