RHSA-2009:1061: Important: freetype security update
FreeType is a free, high-quality, portable font engine that can open andmanage font files. It also loads, hints, and renders individual glyphsefficiently. These packages provide the FreeType 2 font engine.Tavis Ormandy of the Google Security Team discovered several integeroverflow flaws in the FreeType 2 font engine. If a user loaded acarefully-crafted font file with an application linked against FreeType 2,it could cause the application to crash or, possibly, execute arbitrarycode with the privileges of the user running the application.(CVE-2009-0946)Users are advised to upgrade to these updated packages, which contain abackported patch to correct these issues. The X server must be restarted(log out, then log back in) for this update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2009:1061?
The RHSA-2009:1061 vulnerability has been classified as important.
How do I fix RHSA-2009:1061?
You can fix RHSA-2009:1061 by updating to the FreeType version 2.2.1-21.el5_3.
What software is affected by RHSA-2009:1061?
The affected software includes FreeType and its related packages such as freetype-devel and freetype-demos.
Who discovered the RHSA-2009:1061 vulnerability?
The vulnerability was discovered by Tavis Ormandy from the Google Security Team.
What type of vulnerability is RHSA-2009:1061?
RHSA-2009:1061 is an integer overflow vulnerability in the FreeType font engine.