Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.871337
Category:Red Hat Local Security Checks
Title:RedHat Update for freetype RHSA-2015:0696-01
Summary:The remote host is missing an update for the 'freetype'; package(s) announced via the referenced advisory.
Description:Summary:
The remote host is missing an update for the 'freetype'
package(s) announced via the referenced advisory.

Vulnerability Insight:
FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently.

Multiple integer overflow flaws and an integer signedness flaw, leading to
heap-based buffer overflows, were found in the way FreeType handled Mac
fonts. If a specially crafted font file was loaded by an application linked
against FreeType, it could cause the application to crash or, potentially,
execute arbitrary code with the privileges of the user running the
application. (CVE-2014-9673, CVE-2014-9674)

Multiple flaws were found in the way FreeType handled fonts in various
formats. If a specially crafted font file was loaded by an application
linked against FreeType, it could cause the application to crash or,
possibly, disclose a portion of the application memory. (CVE-2014-9657,
CVE-2014-9658, CVE-2014-9660, CVE-2014-9661, CVE-2014-9663, CVE-2014-9664,
CVE-2014-9667, CVE-2014-9669, CVE-2014-9670, CVE-2014-9671, CVE-2014-9675)

All freetype users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The X server must be
restarted (log out, then log back in) for this update to take effect.

Affected Software/OS:
freetype on Red Hat Enterprise Linux Desktop (v. 6),
Red Hat Enterprise Linux Server (v. 6),
Red Hat Enterprise Linux Server (v. 7),
Red Hat Enterprise Linux Workstation (v. 6)

Solution:
Please Install the Updated Packages.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-9657
BugTraq ID: 72986
http://www.securityfocus.com/bid/72986
Debian Security Information: DSA-3188 (Google Search)
http://www.debian.org/security/2015/dsa-3188
http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150162.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150148.html
https://security.gentoo.org/glsa/201503-05
http://www.mandriva.com/security/advisories?name=MDVSA-2015:055
http://code.google.com/p/google-security-research/issues/detail?id=195
RedHat Security Advisories: RHSA-2015:0696
http://rhn.redhat.com/errata/RHSA-2015-0696.html
SuSE Security Announcement: openSUSE-SU-2015:0627 (Google Search)
http://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html
http://www.ubuntu.com/usn/USN-2510-1
http://www.ubuntu.com/usn/USN-2739-1
Common Vulnerability Exposure (CVE) ID: CVE-2014-9658
http://code.google.com/p/google-security-research/issues/detail?id=194
Common Vulnerability Exposure (CVE) ID: CVE-2014-9660
http://code.google.com/p/google-security-research/issues/detail?id=188
Common Vulnerability Exposure (CVE) ID: CVE-2014-9661
http://code.google.com/p/google-security-research/issues/detail?id=187
http://packetstormsecurity.com/files/134396/FreeType-2.5.3-Type42-Parsing-Use-After-Free.html
Common Vulnerability Exposure (CVE) ID: CVE-2014-9663
http://code.google.com/p/google-security-research/issues/detail?id=184
Common Vulnerability Exposure (CVE) ID: CVE-2014-9664
http://code.google.com/p/google-security-research/issues/detail?id=183
Common Vulnerability Exposure (CVE) ID: CVE-2014-9667
http://code.google.com/p/google-security-research/issues/detail?id=166
Common Vulnerability Exposure (CVE) ID: CVE-2014-9669
http://code.google.com/p/google-security-research/issues/detail?id=163
Common Vulnerability Exposure (CVE) ID: CVE-2014-9670
http://code.google.com/p/google-security-research/issues/detail?id=158
Common Vulnerability Exposure (CVE) ID: CVE-2014-9671
http://code.google.com/p/google-security-research/issues/detail?id=157
Common Vulnerability Exposure (CVE) ID: CVE-2014-9673
http://code.google.com/p/google-security-research/issues/detail?id=154
Common Vulnerability Exposure (CVE) ID: CVE-2014-9674
Debian Security Information: DSA-3461 (Google Search)
http://www.debian.org/security/2016/dsa-3461
http://code.google.com/p/google-security-research/issues/detail?id=153
Common Vulnerability Exposure (CVE) ID: CVE-2014-9675
http://code.google.com/p/google-security-research/issues/detail?id=151
CopyrightCopyright (C) 2015 Greenbone Networks GmbH

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2021 E-Soft Inc. All rights reserved.