| Description: | The remote host is missing an update to libt1-5 announced via advisory USN-1335-1.
Details:
Jon Larimer discovered that t1lib did not properly parse AFM fonts. If a user were tricked into using a specially crafted font file, a remote attacker could cause t1lib to crash or possibly execute arbitrary code with user privileges. (CVE-2010-2642, CVE-2011-0433)
Jonathan Brossard discovered that t1lib did not correctly handle certain malformed font files. If a user were tricked into using a specially crafted font file, a remote attacker could cause t1lib to crash. (CVE-2011-1552, CVE-2011-1553, CVE-2011-1554)
Solution: The problem can be corrected by updating your system to the following package versions:
Ubuntu 11.10: libt1-5 5.1.2-3ubuntu0.11.10.2
Ubuntu 11.04: libt1-5 5.1.2-3ubuntu0.11.04.2
Ubuntu 10.10: libt1-5 5.1.2-3ubuntu0.10.10.2
Ubuntu 10.04 LTS: libt1-5 5.1.2-3ubuntu0.10.04.2
http://www.securityspace.com/smysecure/catid.html?in=USN-1335-1 |