blob: c8c43791191a0fcdf2b29b06ee441649dfc60c28 [file] [log] [blame]
<?xml version="1.0" encoding="utf-8"?>
<glsa id="200705-22">
<title>FreeType: Buffer overflow</title>
A vulnerability has been discovered in FreeType allowing for the execution
of arbitrary code.
<product type="ebuild">freetype</product>
<announced>May 30, 2007</announced>
<revised>May 30, 2007: 01</revised>
<package name="media-libs/freetype" auto="yes" arch="*">
<unaffected range="ge">2.3.4-r2</unaffected>
<unaffected range="lt">2.0</unaffected>
<vulnerable range="lt">2.3.4-r2</vulnerable>
FreeType is a True Type Font rendering library.
Victor Stinner discovered a heap-based buffer overflow in the function
Get_VMetrics() in src/truetype/ttgload.c when processing TTF files with
a negative n_points attribute.
<impact type="normal">
A remote attacker could entice a user to open a specially crafted TTF
file, possibly resulting in the execution of arbitrary code with the
privileges of the user running FreeType.
There is no known workaround at this time.
All FreeType users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose &quot;&gt;=media-libs/freetype-2.3.4-r2&quot;</code>
<uri link="">CVE-2007-2754</uri>
<metadata tag="requester" timestamp="Tue, 22 May 2007 15:08:56 +0000">
<metadata tag="submitter" timestamp="Tue, 22 May 2007 15:38:03 +0000">
<metadata tag="bugReady" timestamp="Sun, 27 May 2007 16:46:08 +0000">