RHSA-2010:0578: Important: freetype security update
FreeType is a free, high-quality, portable font engine that can open andmanage font files. It also loads, hints, and renders individual glyphsefficiently. The freetype packages for Red Hat Enterprise Linux 4 provideboth the FreeType 1 and FreeType 2 font engines. The freetype packages forRed Hat Enterprise Linux 5 provide only the FreeType 2 font engine.An invalid memory management flaw was found in the way the FreeType fontengine processed font files. If a user loaded a carefully-crafted font filewith an application linked against FreeType, it could cause the applicationto crash or, possibly, execute arbitrary code with the privileges of theuser running the application. (CVE-2010-2498)An integer overflow flaw was found in the way the FreeType font engineprocessed font files. If a user loaded a carefully-crafted font file withan application linked against FreeType, it could cause the application tocrash or, possibly, execute arbitrary code with the privileges of the userrunning the application. (CVE-2010-2500)Several buffer overflow flaws were found in the way the FreeType fontengine processed font files. If a user loaded a carefully-crafted font filewith an application linked against FreeType, it could cause the applicationto crash or, possibly, execute arbitrary code with the privileges of theuser running the application. (CVE-2010-2499, CVE-2010-2519)Several buffer overflow flaws were found in the FreeType demo applications.If a user loaded a carefully-crafted font file with a demo application, itcould cause the application to crash or, possibly, execute arbitrary codewith the privileges of the user running the application. (CVE-2010-2527,CVE-2010-2541)Red Hat would like to thank Robert Swiecki of the Google Security Team forthe discovery of the CVE-2010-2498, CVE-2010-2500, CVE-2010-2499,CVE-2010-2519, and CVE-2010-2527 issues.Note: All of the issues in this erratum only affect the FreeType 2 fontengine.Users are advised to upgrade to these updated packages, which containbackported patches to correct these issues. The X server must be restarted(log out, then log back in) for this update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2010:0578?
The severity of RHSA-2010:0578 is classified as moderate.
How do I fix RHSA-2010:0578?
To fix RHSA-2010:0578, update the freetype package to the version 2.2.1-25.el5_5 or later.
Which systems are affected by RHSA-2010:0578?
RHSA-2010:0578 affects Red Hat Enterprise Linux 4 and 5 systems running specific versions of the freetype packages.
What are the potential impacts of the vulnerability in RHSA-2010:0578?
The vulnerability in RHSA-2010:0578 may allow an attacker to execute arbitrary code or cause a denial of service.
Is there a workaround for RHSA-2010:0578?
The recommended action for RHSA-2010:0578 is to update the freetype package, and temporary mitigations should not be relied upon as effective solutions.