You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa freetype

Sigurnosni nedostatak programskog paketa freetype

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

Fedora Update Notification
2014-12-13 08:32:24

Name : freetype
Product : Fedora 21
Version : 2.5.3
Release : 13.fc21
Summary : A free and portable font rendering engine
Description :
The FreeType engine is a free and portable font rendering
engine, developed to provide advanced font support for a variety of
platforms and environments. FreeType is a library which can open and
manages font files as well as efficiently load, hint and render
individual glyphs. FreeType is not a font server or a complete
text-rendering library.

Update Information:

This update prevents freetype from a buffer overflow.

* Thu Dec 11 2014 Marek Kasik <> – 2.5.3-13
– Suppress an assert when hintMap.count == 0 in specific situations.
– Related: #1172634
* Wed Dec 10 2014 Marek Kasik <> – 2.5.3-12
– Don’t append to stem arrays after hintmask is constructed.
– Related: #1172634

[ 1 ] Bug #1172633 – freetype: OOB stack-based read/write in cf2_hintmap_build() (incomplete fix for CVE-2014-2240).

This update can be installed with the “yum” update program. Use
su -c ‘yum update freetype’ at the command line.
For more information, refer to “Managing Software with yum”,
available at

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list

AutorMarijo Plepelic
Cert idNCERT-REF-2014-12-0036-ADV
More in Preporuke
Ranjivost programskog paketa xntp

Otkrivena je kritična ranjivost u programskom paketu xntp za SUSE LE Server 10 SP4 LTSS. Ranjivost je posljedica višestrukog prepisivanja...