RHSA-2006:0500: freetype security update

Published Jul 18, 2006
·
Updated

FreeType is a free, high-quality, and portable font engine.Chris Evans discovered several integer underflow and overflow flaws in theFreeType font engine. If a user loads a carefully crafted font file with aprogram linked against FreeType, it could cause the application to crash orexecute arbitrary code as the user. While it is uncommon for a user toexplicitly load a font file, there are several application file formatswhich contain embedded fonts that are parsed by FreeType. (CVE-2006-0747,CVE-2006-1861, CVE-2006-3467)A NULL pointer dereference flaw was found in the FreeType font engine. Anapplication linked against FreeType can crash upon loading a malformed fontfile. (CVE-2006-2661)Users of FreeType should upgrade to these updated packages, which containbackported patches to correct these issues.

Affected Software

8 affected componentsFixes available
redhat/freetype<2.1.9-1.rhel4.4
2.1.9-1.rhel4.4
redhat/freetype<2.1.9-1.rhel4.4
2.1.9-1.rhel4.4
redhat/freetype-demos<2.1.9-1.rhel4.4
2.1.9-1.rhel4.4
redhat/freetype-devel<2.1.9-1.rhel4.4
2.1.9-1.rhel4.4
redhat/freetype-utils<2.1.9-1.rhel4.4
2.1.9-1.rhel4.4
redhat/freetype-demos<2.1.9-1.rhel4.4
2.1.9-1.rhel4.4
redhat/freetype-devel<2.1.9-1.rhel4.4
2.1.9-1.rhel4.4
redhat/freetype-utils<2.1.9-1.rhel4.4
2.1.9-1.rhel4.4

Remediation

Event History

Jul 18, 2006
Advisory Published
12:00 AM

Frequently Asked Questions

1

What is the severity of RHSA-2006:0500?

The severity of RHSA-2006:0500 is classified as moderate.

2

How do I fix RHSA-2006:0500?

To fix RHSA-2006:0500, upgrade to the FreeType version 2.1.9-1.rhel4.4 or later.

3

What are the impacts of RHSA-2006:0500?

The impacts of RHSA-2006:0500 can include application crashes or arbitrary code execution if a malicious font file is processed.

4

Which packages are affected by RHSA-2006:0500?

The affected packages include freetype, freetype-devel, freetype-utils, and freetype-demos in specific versions.

5

Is it safe to continue using systems with RHSA-2006:0500 vulnerability?

It is not safe to continue using systems with the RHSA-2006:0500 vulnerability as it can be exploited through malicious font files.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203