Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.68448
Category:Fedora Local Security Checks
Title:Fedora Core 13 FEDORA-2010-15705 (freetype)
Summary:NOSUMMARY
Description:Description:
The remote host is missing an update to freetype
announced via advisory FEDORA-2010-15705.

References:

[ 1 ] Bug #613160 - CVE-2010-2498 freetype: invalid free vulnerability with possible heap corruption
https://bugzilla.redhat.com/show_bug.cgi?id=613160
[ 2 ] Bug #613162 - CVE-2010-2499 freetype: buffer overflow vulnerability
https://bugzilla.redhat.com/show_bug.cgi?id=613162
[ 3 ] Bug #613167 - CVE-2010-2500 freetype: integer overflow vulnerability in smooth/ftgrays.c
https://bugzilla.redhat.com/show_bug.cgi?id=613167
[ 4 ] Bug #613194 - CVE-2010-2519 freetype: heap buffer overflow vulnerability when processing certain font files
https://bugzilla.redhat.com/show_bug.cgi?id=613194
[ 5 ] Bug #613198 - CVE-2010-2520 freetype: heap buffer overflow vulnerability in truetype bytecode support
https://bugzilla.redhat.com/show_bug.cgi?id=613198
[ 6 ] Bug #614557 - CVE-2010-2527 Freetype demos multiple buffer overflows
https://bugzilla.redhat.com/show_bug.cgi?id=614557
[ 7 ] Bug #617342 - CVE-2010-2541 Freetype ftmulti buffer overflow
https://bugzilla.redhat.com/show_bug.cgi?id=617342
[ 8 ] Bug #621144 - CVE-2010-1797 FreeType: Multiple stack overflows by processing CFF opcodes
https://bugzilla.redhat.com/show_bug.cgi?id=621144
[ 9 ] Bug #621907 - CVE-2010-2808 FreeType: Stack-based buffer overflow by processing certain LWFN fonts
https://bugzilla.redhat.com/show_bug.cgi?id=621907
[ 10 ] Bug #621980 - CVE-2010-2806 FreeType: Heap-based buffer overflow by processing FontType42 fonts with negative length of SFNT strings (FT bug #30656)
https://bugzilla.redhat.com/show_bug.cgi?id=621980
[ 11 ] Bug #623625 - CVE-2010-3311 freetype: Input stream position error by processing Compact Font Format (CFF) font files
https://bugzilla.redhat.com/show_bug.cgi?id=623625
[ 12 ] Bug #625626 - CVE-2010-2805 freetype: FT_Stream_EnterFrame() does not properly validate certain position values
https://bugzilla.redhat.com/show_bug.cgi?id=625626

Solution: Apply the appropriate updates.

This update can be installed with the yum update program. Use
su -c 'yum update freetype' at the command line.
For more information, refer to Managing Software with yum,
available at http://docs.fedoraproject.org/yum/.

http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2010-15705

Risk factor : Critical

CVSS Score:
9.3

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2010-2805
http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html
http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html
BugTraq ID: 42285
http://www.securityfocus.com/bid/42285
http://marc.info/?l=oss-security&m=128111955616772&w=2
http://www.redhat.com/support/errata/RHSA-2010-0864.html
http://secunia.com/advisories/40816
http://secunia.com/advisories/40982
http://secunia.com/advisories/42314
http://secunia.com/advisories/42317
http://secunia.com/advisories/48951
http://www.ubuntu.com/usn/USN-972-1
http://www.vupen.com/english/advisories/2010/2018
http://www.vupen.com/english/advisories/2010/2106
http://www.vupen.com/english/advisories/2010/3045
http://www.vupen.com/english/advisories/2010/3046
Common Vulnerability Exposure (CVE) ID: CVE-2010-2806
RedHat Security Advisories: RHSA-2010:0736
https://rhn.redhat.com/errata/RHSA-2010-0736.html
RedHat Security Advisories: RHSA-2010:0737
https://rhn.redhat.com/errata/RHSA-2010-0737.html
Common Vulnerability Exposure (CVE) ID: CVE-2010-2808
http://marc.info/?l=oss-security&m=128110167119337&w=2
Common Vulnerability Exposure (CVE) ID: CVE-2010-3311
BugTraq ID: 43700
http://www.securityfocus.com/bid/43700
Debian Security Information: DSA-2116 (Google Search)
http://www.debian.org/security/2010/dsa-2116
http://www.mandriva.com/security/advisories?name=MDVSA-2010:201
SuSE Security Announcement: SUSE-SR:2010:019 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html
http://www.ubuntu.com/usn/USN-1013-1
Common Vulnerability Exposure (CVE) ID: CVE-2010-1797
http://lists.apple.com/archives/security-announce/2010//Aug/msg00000.html
http://lists.apple.com/archives/security-announce/2010//Aug/msg00001.html
BugTraq ID: 42151
http://www.securityfocus.com/bid/42151
http://www.exploit-db.com/exploits/14538
http://www.f-secure.com/weblog/archives/00002002.html
http://osvdb.org/66828
http://secunia.com/advisories/40807
XForce ISS Database: appleios-pdf-code-execution(60856)
https://exchange.xforce.ibmcloud.com/vulnerabilities/60856
Common Vulnerability Exposure (CVE) ID: CVE-2010-2498
Debian Security Information: DSA-2070 (Google Search)
http://www.debian.org/security/2010/dsa-2070
http://www.mandriva.com/security/advisories?name=MDVSA-2010:137
http://lists.nongnu.org/archive/html/freetype/2010-07/msg00001.html
http://marc.info/?l=oss-security&m=127905701201340&w=2
http://marc.info/?l=oss-security&m=127909326909362&w=2
http://www.redhat.com/support/errata/RHSA-2010-0578.html
http://securitytracker.com/id?1024266
http://www.ubuntu.com/usn/USN-963-1
Common Vulnerability Exposure (CVE) ID: CVE-2010-2499
Common Vulnerability Exposure (CVE) ID: CVE-2010-2500
http://www.redhat.com/support/errata/RHSA-2010-0577.html
Common Vulnerability Exposure (CVE) ID: CVE-2010-2519
Common Vulnerability Exposure (CVE) ID: CVE-2010-2520
Common Vulnerability Exposure (CVE) ID: CVE-2010-2527
http://marc.info/?l=oss-security&m=127912955808467&w=2
Common Vulnerability Exposure (CVE) ID: CVE-2010-2541
CopyrightCopyright (c) 2010 E-Soft Inc. http://www.securityspace.com

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2022 E-Soft Inc. All rights reserved.