RHSA-2009:1062: Important: freetype security update
FreeType is a free, high-quality, portable font engine that can open andmanage font files. It also loads, hints, and renders individual glyphsefficiently. These packages provide both the FreeType 1 and FreeType 2font engines.Tavis Ormandy of the Google Security Team discovered several integeroverflow flaws in the FreeType 2 font engine. If a user loaded acarefully-crafted font file with an application linked against FreeType 2,it could cause the application to crash or, possibly, execute arbitrarycode with the privileges of the user running the application.(CVE-2009-0946)Chris Evans discovered multiple integer overflow flaws in the FreeType fontengine. If a user loaded a carefully-crafted font file with an applicationlinked against FreeType, it could cause the application to crash or,possibly, execute arbitrary code with the privileges of the user runningthe application. (CVE-2006-1861)An integer overflow flaw was found in the way the FreeType font engineprocessed TrueType® Font (TTF) files. If a user loaded a carefully-craftedfont file with an application linked against FreeType, it could cause theapplication to crash or, possibly, execute arbitrary code with theprivileges of the user running the application. (CVE-2007-2754)Note: For the FreeType 2 font engine, the CVE-2006-1861 and CVE-2007-2754flaws were addressed via RHSA-2006:0500 and RHSA-2007:0403 respectively.This update provides corresponding updates for the FreeType 1 font engine,included in the freetype packages distributed in Red Hat Enterprise Linux2.1.Users are advised to upgrade to these updated packages, which containbackported patches to correct these issues. The X server must be restarted(log out, then log back in) for this update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2009:1062?
The severity of RHSA-2009:1062 is classified as important.
How do I fix RHSA-2009:1062?
To fix RHSA-2009:1062, update the FreeType package to the latest version provided by the vendor.
What software is affected by RHSA-2009:1062?
RHSA-2009:1062 affects various packages that include FreeType 1 and FreeType 2 font engines.
What vulnerabilities are addressed in RHSA-2009:1062?
RHSA-2009:1062 addresses multiple vulnerabilities related to memory corruption in FreeType.
Is a reboot required after applying the fix for RHSA-2009:1062?
A reboot is not required, but restarting the affected services is recommended after applying the fix for RHSA-2009:1062.