RHSA-2006:0500: freetype security update
FreeType is a free, high-quality, and portable font engine.Chris Evans discovered several integer underflow and overflow flaws in theFreeType font engine. If a user loads a carefully crafted font file with aprogram linked against FreeType, it could cause the application to crash orexecute arbitrary code as the user. While it is uncommon for a user toexplicitly load a font file, there are several application file formatswhich contain embedded fonts that are parsed by FreeType. (CVE-2006-0747,CVE-2006-1861, CVE-2006-3467)A NULL pointer dereference flaw was found in the FreeType font engine. Anapplication linked against FreeType can crash upon loading a malformed fontfile. (CVE-2006-2661)Users of FreeType should upgrade to these updated packages, which containbackported patches to correct these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2006:0500?
The severity of RHSA-2006:0500 is classified as moderate.
How do I fix RHSA-2006:0500?
To fix RHSA-2006:0500, upgrade to the FreeType version 2.1.9-1.rhel4.4 or later.
What are the impacts of RHSA-2006:0500?
The impacts of RHSA-2006:0500 can include application crashes or arbitrary code execution if a malicious font file is processed.
Which packages are affected by RHSA-2006:0500?
The affected packages include freetype, freetype-devel, freetype-utils, and freetype-demos in specific versions.
Is it safe to continue using systems with RHSA-2006:0500 vulnerability?
It is not safe to continue using systems with the RHSA-2006:0500 vulnerability as it can be exploited through malicious font files.