You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa freetype

Sigurnosni nedostatak programskog paketa freetype

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-4593-1
October 20, 2020

freetype vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 20.04 LTS
– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS

Summary:

FreeType could be made to crash or run programs as your login if it
opened a specially crafted file.

Software Description:
– freetype: FreeType 2 is a font engine library

Details:

Sergei Glazunov discovered that FreeType did not correctly handle certain
malformed font files. If a user were tricked into using a specially crafted
font file, a remote attacker could cause FreeType to crash or possibly
execute arbitrary code with user privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
libfreetype6 2.10.1-2ubuntu0.1

Ubuntu 18.04 LTS:
libfreetype6 2.8.1-2ubuntu2.1

Ubuntu 16.04 LTS:
libfreetype6 2.6.1-0.1ubuntu2.5

After a standard system update you need to restart your session to make
all the necessary changes.

References:
https://usn.ubuntu.com/4593-1
CVE-2020-15999

Package Information:
https://launchpad.net/ubuntu/+source/freetype/2.10.1-2ubuntu0.1
https://launchpad.net/ubuntu/+source/freetype/2.8.1-2ubuntu2.1
https://launchpad.net/ubuntu/+source/freetype/2.6.1-0.1ubuntu2.5
—–BEGIN PGP SIGNATURE—–

iQFOBAEBCgA4FiEEiOlTC8vdwgBRe16w9JjS2d59rZwFAl+O080aHGFsZXgubXVy
cmF5QGNhbm9uaWNhbC5jb20ACgkQ9JjS2d59rZxC7AgAqhAKs1N7RIPDHjo/329/
kqKUb7h5w5PsowmMXfxzTlBOyLnAaLXjVg1sqGnVdBTb10xtNRKr7P/0Z2+IbNMy
MBvLAeWrn6NkTSmQcAhv0HGn9shQj8K89SrLX18VF/94LKUlcL6E2ykAp2Tp5rzy
fxndvTuiiB9kcKA6lgfWksxe3G6MIzzCfUSrrxxJsiRyXbBbydGt2svYQeizZcTB
zsaFDKwUZ/e3KcA1z2jrhD+r9R+HooPcqagaJXDEmQK/N5aRPmYeLGUvBpd8VHhz
m4LrNXTQ4ih66zHPZADDah9plKan3siVJDqfNjqKLsAYwha3T+pn48fpwLb0f5Vp
Ug==
=HjYN
—–END PGP SIGNATURE——-

AutorBruno Varga
Cert idNCERT-REF-2020-10-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostaci jezgre operacijskog sustava

Otkriveni su sigurnosni nedostaci jezgre operacijskog sustava RHEL. Otkriveni nedostaci potencijalnim napadačima omogućuju izazivanje DoS stanja, izvršavanje proizvoljnog programskog koda,...

Close