You are here
Home > Preporuke > Ranjivost programske biblioteke freetype

Ranjivost programske biblioteke freetype

  • Detalji os-a: FED
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

Fedora Update Notification
2014-12-13 08:33:02

Name : freetype
Product : Fedora 20
Version : 2.5.0
Release : 7.fc20
Summary : A free and portable font rendering engine
Description :
The FreeType engine is a free and portable font rendering
engine, developed to provide advanced font support for a variety of
platforms and environments. FreeType is a library which can open and
manages font files as well as efficiently load, hint and render
individual glyphs. FreeType is not a font server or a complete
text-rendering library.

Update Information:

This update prevents freetype from a buffer overflow.

* Thu Dec 11 2014 Marek Kasik <> – 2.5.0-7
– Suppress an assert when hintMap.count == 0 in specific situations.
– Resolves: #1172634
* Wed Dec 10 2014 Marek Kasik <> – 2.5.0-6
– Don’t append to stem arrays after hintmask is constructed.
– Resolves: #1172634
* Tue Mar 11 2014 Marek Kasik <> – 2.5.0-5
– Add freetype-2.5.0-CVE-2014-2240.patch
(Return when `hintMask’ is invalid.)
– Add freetype-2.5.0-CVE-2014-2241.patch
(Don’t call non-existing subroutines.)
– Resolves: #1074647

[ 1 ] Bug #1172633 – freetype: OOB stack-based read/write in cf2_hintmap_build() (incomplete fix for CVE-2014-2240).

This update can be installed with the “yum” update program. Use
su -c ‘yum update freetype’ at the command line.
For more information, refer to “Managing Software with yum”,
available at

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list

AutorTomislav Protega
Cert idNCERT-REF-2015-01-0016-ADV
CveCVE-2014-2240 CVE-2014-2241
ID izvornikaFEDORA-2014-16854
More in Preporuke
Ranjivost programskog paketa mailx

Otkrivena je ranjivost u implementaciji "mail" naredbe - mailx, za Fedoru. Ranjivost se očitovala načinom kojim je mailx upravljao parsiranjem...