Login
Newsletter
Werbung

Sicherheit: Ausführen beliebiger Kommandos in FreeType
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in FreeType
ID: USN-4593-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
Datum: Di, 20. Oktober 2020, 17:36
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15999
Applikationen: Freetype

Originalnachricht

--===============1316106136282637015==
Content-Type: multipart/signed; boundary="=-=-=";
micalg=pgp-sha512; protocol="application/pgp-signature"

--=-=-=
Content-Type: text/plain

==========================================================================
Ubuntu Security Notice USN-4593-1
October 20, 2020

freetype vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

FreeType could be made to crash or run programs as your login if it
opened a specially crafted file.

Software Description:
- freetype: FreeType 2 is a font engine library

Details:

Sergei Glazunov discovered that FreeType did not correctly handle certain
malformed font files. If a user were tricked into using a specially crafted
font file, a remote attacker could cause FreeType to crash or possibly
execute arbitrary code with user privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
libfreetype6 2.10.1-2ubuntu0.1

Ubuntu 18.04 LTS:
libfreetype6 2.8.1-2ubuntu2.1

Ubuntu 16.04 LTS:
libfreetype6 2.6.1-0.1ubuntu2.5

After a standard system update you need to restart your session to make
all the necessary changes.

References:
https://usn.ubuntu.com/4593-1
CVE-2020-15999

Package Information:
https://launchpad.net/ubuntu/+source/freetype/2.10.1-2ubuntu0.1
https://launchpad.net/ubuntu/+source/freetype/2.8.1-2ubuntu2.1
https://launchpad.net/ubuntu/+source/freetype/2.6.1-0.1ubuntu2.5

--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQFOBAEBCgA4FiEEiOlTC8vdwgBRe16w9JjS2d59rZwFAl+O080aHGFsZXgubXVy
cmF5QGNhbm9uaWNhbC5jb20ACgkQ9JjS2d59rZxC7AgAqhAKs1N7RIPDHjo/329/
kqKUb7h5w5PsowmMXfxzTlBOyLnAaLXjVg1sqGnVdBTb10xtNRKr7P/0Z2+IbNMy
MBvLAeWrn6NkTSmQcAhv0HGn9shQj8K89SrLX18VF/94LKUlcL6E2ykAp2Tp5rzy
fxndvTuiiB9kcKA6lgfWksxe3G6MIzzCfUSrrxxJsiRyXbBbydGt2svYQeizZcTB
zsaFDKwUZ/e3KcA1z2jrhD+r9R+HooPcqagaJXDEmQK/N5aRPmYeLGUvBpd8VHhz
m4LrNXTQ4ih66zHPZADDah9plKan3siVJDqfNjqKLsAYwha3T+pn48fpwLb0f5Vp
Ug==
=HjYN
-----END PGP SIGNATURE-----
--=-=-=--


--===============1316106136282637015==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung