You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa freetype

Sigurnosni nedostaci programskog paketa freetype

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

Fedora Update Notification
2014-03-12 09:19:38

Name : freetype
Product : Fedora 20
Version : 2.5.0
Release : 5.fc20
Summary : A free and portable font rendering engine
Description :
The FreeType engine is a free and portable font rendering
engine, developed to provide advanced font support for a variety of
platforms and environments. FreeType is a library which can open and
manages font files as well as efficiently load, hint and render
individual glyphs. FreeType is not a font server or a complete
text-rendering library.

Update Information:

This update fixes two security issues of the CFF engine (#1074647, #1074646).

* Tue Mar 11 2014 Marek Kasik <> – 2.5.0-5
– Add freetype-2.5.0-CVE-2014-2240.patch
(Return when `hintMask’ is invalid.)
– Add freetype-2.5.0-CVE-2014-2241.patch
(Don’t call non-existing subroutines.)
– Resolves: #1074647

This update can be installed with the “yum” update program. Use
su -c ‘yum update freetype’ at the command line.
For more information, refer to “Managing Software with yum”,
available at

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list

AutorMarijo Plepelic
Cert idNCERT-REF-2014-03-0013-ADV
More in Preporuke
Sigurnosni nedostatak programskog paketa libssh

Otkriven je sigurnosni nedostatak u programskom paketu libssh za operacijski sustav Fedora 19. Otkriveni nedostatak potencijalnim napadačima omogućuje otkrivanje informacija,...