FreeType Printer Font Binary Heap Buffer Overflow Vulnerability
BID:29637
Info
FreeType Printer Font Binary Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 29637 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1808 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2008 12:00AM |
| Updated: | Mar 19 2015 09:29AM |
| Credit: | regenrecht |
| Vulnerable: |
VMWare Workstation 6.0.5 build 109488 VMWare Workstation 6.0.5 VMWare Workstation 5.5.8 build 108000 VMWare Workstation 5.5.8 VMWare Server 1.0.7 build 108231 VMWare Server 1.0.7 VMWare Player 2.0.5 build 109488 VMWare Player 2.0.5 VMWare Player 1.0.8 build 108000 VMWare Player 1.0.8 VMWare Fusion 1.1.2 VMWare Fusion 1.1.1 VMWare Fusion 1.1 VMWare Fusion 1.1.2 build 87978 VMWare Fusion 1.0 VMWare ESX Server 2.5.5 VMWare ESX Server 2.5.4 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 lpia Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE openSUSE 10.3 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Desktop 1.0 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc rPath rPath Linux 2 rPath rPath Linux 1 rPath Appliance Platform Linux Service 2 rPath Appliance Platform Linux Service 1 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux WS 2.1 IA64 RedHat Enterprise Linux WS 2.1 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux ES 2.1 IA64 RedHat Enterprise Linux ES 2.1 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Desktop 4.0 RedHat Desktop 3.0 RedHat Advanced Workstation for the Itanium Processor 2.1 IA64 RedHat Advanced Workstation for the Itanium Processor 2.1 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux AS 2.1 IA64 Red Hat Enterprise Linux AS 2.1 Red Hat Enterprise Linux 5 Server MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Gentoo Linux FreeType FreeType 2.3.5 FreeType FreeType 2.3.4 FreeType FreeType 2.3.3 FreeType FreeType 2.2.10 FreeType FreeType 2.2.1 FreeType FreeType 2.1.10 FreeType FreeType 2.1.9 FreeType FreeType 2.1.7 FreeType FreeType 2.0.9 FreeType FreeType 2.0.6 FreeType FreeType 2.2 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Voice Portal 4.1 Avaya Voice Portal 4.0 Avaya Proactive Contact 3.0.2 Avaya Proactive Contact 4.1 Avaya Proactive Contact 4.0 Avaya Proactive Contact 3.0 Avaya Proactive Contact 0 Avaya Message Networking MN 3.1 Avaya Message Networking 3.1 Avaya Message Networking Avaya Intuity AUDIX LX 2.0 SP2 Avaya Intuity AUDIX LX 2.0 SP1 Avaya Intuity AUDIX LX 2.0 Avaya Intuity AUDIX LX 1.0 Avaya Intuity AUDIX Avaya EMMC 1.017 Avaya EMMC 0 Avaya Communication Manager 3.0 Avaya Aura Application Enablement Services 4.2.2 Avaya Aura Application Enablement Services 4.2.1 Avaya Aura Application Enablement Services 4.0.1 Avaya Aura Application Enablement Services 3.1.6 Avaya Aura Application Enablement Services 3.1.5 Avaya Aura Application Enablement Services 3.1.4 Avaya Aura Application Enablement Services 3.1.3 Avaya Aura Application Enablement Services 4.2 Avaya Aura Application Enablement Services 4.1 Avaya Aura Application Enablement Services 4.0 Avaya Aura Application Enablement Services 3.1 Avaya Aura Application Enablement Services 3.0 Apple iPod Touch 2.0.2 Apple iPod Touch 2.0.1 Apple iPod Touch 1.1.4 Apple iPod Touch 1.1.3 Apple iPod Touch 1.1.2 Apple iPod Touch 1.1.1 Apple iPod Touch 2.0 Apple iPod Touch 1.1 Apple iPhone 2.0.2 Apple iPhone 2.0.1 Apple iPhone 1.1.4 Apple iPhone 1.1.3 Apple iPhone 1.1.2 Apple iPhone 1.1.1 Apple iPhone 1.0.2 Apple iPhone 1.0.1 Apple iPhone 2.0 Apple iPhone 1.1 Apple iPhone 1 Apple iPhone 0 |
| Not Vulnerable: |
FreeType FreeType 2.3.6 Apple iPod Touch 2.1 Apple iPhone 2.1 |
Discussion
FreeType Printer Font Binary Heap Buffer Overflow Vulnerability
FreeType is prone to a heap-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code within the context of the application using the FreeType library. Failed exploit attempts will result in a denial-of-service vulnerability.
NOTE: This issue may allow a local attacker using X.Org Xserver to gain elevated privileges on the affected computer.
Successfully exploiting this issue will result in the complete compromise of affected computers.
FreeType 2.3.5 is vulnerable; other versions may also be affected.
FreeType is prone to a heap-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code within the context of the application using the FreeType library. Failed exploit attempts will result in a denial-of-service vulnerability.
NOTE: This issue may allow a local attacker using X.Org Xserver to gain elevated privileges on the affected computer.
Successfully exploiting this issue will result in the complete compromise of affected computers.
FreeType 2.3.5 is vulnerable; other versions may also be affected.
Exploit / POC
FreeType Printer Font Binary Heap Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
FreeType Printer Font Binary Heap Buffer Overflow Vulnerability
Solution:
The vendor released FreeType 2.3.6 to address this issue. Please see the references for more information.
Ubuntu Ubuntu Linux 7.10 powerpc
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
Ubuntu Ubuntu Linux 7.04 i386
Debian Linux 4.0 mips
Debian Linux 4.0 arm
Debian Linux 4.0 powerpc
Ubuntu Ubuntu Linux 7.04 amd64
Ubuntu Ubuntu Linux 8.04 LTS lpia
Ubuntu Ubuntu Linux 7.10 lpia
Ubuntu Ubuntu Linux 6.06 LTS i386
Debian Linux 4.0 sparc
Ubuntu Ubuntu Linux 7.10 amd64
Ubuntu Ubuntu Linux 8.04 LTS i386
Ubuntu Ubuntu Linux 7.04 powerpc
FreeType FreeType 2.0.9
FreeType FreeType 2.1.7
FreeType FreeType 2.3.3
FreeType FreeType 2.3.4
MandrakeSoft Corporate Server 3.0
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
The vendor released FreeType 2.3.6 to address this issue. Please see the references for more information.
Ubuntu Ubuntu Linux 7.10 powerpc
-
Ubuntu freetype2-demos_2.3.5-1ubuntu4.7.10.1_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/freetype2-d emos_2.3.5-1ubuntu4.7.10.1_powerpc.deb -
Ubuntu libfreetype6-dev_2.3.5-1ubuntu4.7.10.1_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6-de v_2.3.5-1ubuntu4.7.10.1_powerpc.deb -
Ubuntu libfreetype6-udeb_2.3.5-1ubuntu4.7.10.1_powerpc.udeb
http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/libfreetype 6-udeb_2.3.5-1ubuntu4.7.10.1_powerpc.udeb -
Ubuntu libfreetype6_2.3.5-1ubuntu4.7.10.1_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6_2. 3.5-1ubuntu4.7.10.1_powerpc.deb
Debian Linux 4.0 amd64
-
Debian freetype2-demos_2.2.1-5+etch3_amd64.deb
http://security.debian.org/pool/updates/main/f/freetype/freetype2-demo s_2.2.1-5+etch3_amd64.deb -
Debian libfreetype6-dev_2.2.1-5+etch3_amd64.deb
http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-d ev_2.2.1-5+etch3_amd64.deb -
Debian libfreetype6-udeb_2.2.1-5+etch3_amd64.udeb
http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-u deb_2.2.1-5+etch3_amd64.udeb -
Debian libfreetype6_2.2.1-5+etch3_amd64.deb
http://security.debian.org/pool/updates/main/f/freetype/libfreetype6_2 .2.1-5+etch3_amd64.deb
Debian Linux 4.0 ia-32
-
Debian freetype2-demos_2.2.1-5+etch3_i386.deb
http://security.debian.org/pool/updates/main/f/freetype/freetype2-demo s_2.2.1-5+etch3_i386.deb -
Debian libfreetype6-dev_2.2.1-5+etch3_i386.deb
http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-d ev_2.2.1-5+etch3_i386.deb -
Debian libfreetype6-udeb_2.2.1-5+etch3_i386.udeb
http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-u deb_2.2.1-5+etch3_i386.udeb -
Debian libfreetype6_2.2.1-5+etch3_i386.deb
http://security.debian.org/pool/updates/main/f/freetype/libfreetype6_2 .2.1-5+etch3_i386.deb
Ubuntu Ubuntu Linux 7.04 i386
-
Ubuntu freetype2-demos_2.2.1-5ubuntu1.2_i386.deb
http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/freetype2-d emos_2.2.1-5ubuntu1.2_i386.deb -
Ubuntu libfreetype6-dev_2.2.1-5ubuntu1.2_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6-de v_2.2.1-5ubuntu1.2_i386.deb -
Ubuntu libfreetype6-udeb_2.2.1-5ubuntu1.2_i386.udeb
http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/libfreetype 6-udeb_2.2.1-5ubuntu1.2_i386.udeb -
Ubuntu libfreetype6_2.2.1-5ubuntu1.2_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6_2. 2.1-5ubuntu1.2_i386.deb
Debian Linux 4.0 mips
-
Debian freetype2-demos_2.2.1-5+etch3_mips.deb
http://security.debian.org/pool/updates/main/f/freetype/freetype2-demo s_2.2.1-5+etch3_mips.deb -
Debian libfreetype6-dev_2.2.1-5+etch3_mips.deb
http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-d ev_2.2.1-5+etch3_mips.deb -
Debian libfreetype6-udeb_2.2.1-5+etch3_mips.udeb
http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-u deb_2.2.1-5+etch3_mips.udeb -
Debian libfreetype6_2.2.1-5+etch3_mips.deb
http://security.debian.org/pool/updates/main/f/freetype/libfreetype6_2 .2.1-5+etch3_mips.deb
Debian Linux 4.0 arm
-
Debian freetype2-demos_2.2.1-5+etch3_arm.deb
http://security.debian.org/pool/updates/main/f/freetype/freetype2-demo s_2.2.1-5+etch3_arm.deb -
Debian libfreetype6-dev_2.2.1-5+etch3_arm.deb
http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-d ev_2.2.1-5+etch3_arm.deb -
Debian libfreetype6-udeb_2.2.1-5+etch3_arm.udeb
http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-u deb_2.2.1-5+etch3_arm.udeb -
Debian libfreetype6_2.2.1-5+etch3_arm.deb
http://security.debian.org/pool/updates/main/f/freetype/libfreetype6_2 .2.1-5+etch3_arm.deb
Debian Linux 4.0 powerpc
-
Debian freetype2-demos_2.2.1-5+etch3_powerpc.deb
http://security.debian.org/pool/updates/main/f/freetype/freetype2-demo s_2.2.1-5+etch3_powerpc.deb -
Debian libfreetype6-dev_2.2.1-5+etch3_powerpc.deb
http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-d ev_2.2.1-5+etch3_powerpc.deb -
Debian libfreetype6-udeb_2.2.1-5+etch3_powerpc.udeb
http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-u deb_2.2.1-5+etch3_powerpc.udeb -
Debian libfreetype6_2.2.1-5+etch3_powerpc.deb
http://security.debian.org/pool/updates/main/f/freetype/libfreetype6_2 .2.1-5+etch3_powerpc.deb
Ubuntu Ubuntu Linux 7.04 amd64
-
Ubuntu freetype2-demos_2.2.1-5ubuntu1.2_amd64.deb
http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/freetype2-d emos_2.2.1-5ubuntu1.2_amd64.deb -
Ubuntu libfreetype6-dev_2.2.1-5ubuntu1.2_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6-de v_2.2.1-5ubuntu1.2_amd64.deb -
Ubuntu libfreetype6-udeb_2.2.1-5ubuntu1.2_amd64.udeb
http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/libfreetype 6-udeb_2.2.1-5ubuntu1.2_amd64.udeb -
Ubuntu libfreetype6_2.2.1-5ubuntu1.2_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6_2. 2.1-5ubuntu1.2_amd64.deb
Ubuntu Ubuntu Linux 8.04 LTS lpia
-
Ubuntu freetype2-demos_2.3.5-1ubuntu4.8.04.1_lpia.deb
http://ports.ubuntu.com/pool/universe/f/freetype/freetype2-demos_2.3.5 -1ubuntu4.8.04.1_lpia.deb -
Ubuntu libfreetype6-dev_2.3.5-1ubuntu4.8.04.1_lpia.deb
http://ports.ubuntu.com/pool/main/f/freetype/libfreetype6-dev_2.3.5-1u buntu4.8.04.1_lpia.deb -
Ubuntu libfreetype6-udeb_2.3.5-1ubuntu4.8.04.1_lpia.udeb
http://ports.ubuntu.com/pool/universe/f/freetype/libfreetype6-udeb_2.3 .5-1ubuntu4.8.04.1_lpia.udeb -
Ubuntu libfreetype6_2.3.5-1ubuntu4.8.04.1_lpia.deb
http://ports.ubuntu.com/pool/main/f/freetype/libfreetype6_2.3.5-1ubunt u4.8.04.1_lpia.deb
Ubuntu Ubuntu Linux 7.10 lpia
-
Ubuntu freetype2-demos_2.3.5-1ubuntu4.7.10.1_lpia.deb
http://ports.ubuntu.com/pool/universe/f/freetype/freetype2-demos_2.3.5 -1ubuntu4.7.10.1_lpia.deb -
Ubuntu libfreetype6-dev_2.3.5-1ubuntu4.7.10.1_lpia.deb
http://ports.ubuntu.com/pool/main/f/freetype/libfreetype6-dev_2.3.5-1u buntu4.7.10.1_lpia.deb -
Ubuntu libfreetype6-udeb_2.3.5-1ubuntu4.7.10.1_lpia.udeb
http://ports.ubuntu.com/pool/universe/f/freetype/libfreetype6-udeb_2.3 .5-1ubuntu4.7.10.1_lpia.udeb -
Ubuntu libfreetype6_2.3.5-1ubuntu4.7.10.1_lpia.deb
http://ports.ubuntu.com/pool/main/f/freetype/libfreetype6_2.3.5-1ubunt u4.7.10.1_lpia.deb
Ubuntu Ubuntu Linux 6.06 LTS i386
-
Ubuntu freetype2-demos_2.1.10-1ubuntu2.5_i386.deb
http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/freetype2-d emos_2.1.10-1ubuntu2.5_i386.deb -
Ubuntu libfreetype6-dev_2.1.10-1ubuntu2.5_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6-de v_2.1.10-1ubuntu2.5_i386.deb -
Ubuntu libfreetype6-udeb_2.1.10-1ubuntu2.5_i386.udeb
http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/libfreetype 6-udeb_2.1.10-1ubuntu2.5_i386.udeb -
Ubuntu libfreetype6_2.1.10-1ubuntu2.5_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6_2. 1.10-1ubuntu2.5_i386.deb
Debian Linux 4.0 sparc
-
Debian freetype2-demos_2.2.1-5+etch3_sparc.deb
http://security.debian.org/pool/updates/main/f/freetype/freetype2-demo s_2.2.1-5+etch3_sparc.deb -
Debian libfreetype6-dev_2.2.1-5+etch3_sparc.deb
http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-d ev_2.2.1-5+etch3_sparc.deb -
Debian libfreetype6-udeb_2.2.1-5+etch3_sparc.udeb
http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-u deb_2.2.1-5+etch3_sparc.udeb -
Debian libfreetype6_2.2.1-5+etch3_sparc.deb
http://security.debian.org/pool/updates/main/f/freetype/libfreetype6_2 .2.1-5+etch3_sparc.deb
Ubuntu Ubuntu Linux 7.10 amd64
-
Ubuntu freetype2-demos_2.3.5-1ubuntu4.7.10.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/freetype2-d emos_2.3.5-1ubuntu4.7.10.1_amd64.deb -
Ubuntu libfreetype6-dev_2.3.5-1ubuntu4.7.10.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6-de v_2.3.5-1ubuntu4.7.10.1_amd64.deb -
Ubuntu libfreetype6-udeb_2.3.5-1ubuntu4.7.10.1_amd64.udeb
http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/libfreetype 6-udeb_2.3.5-1ubuntu4.7.10.1_amd64.udeb -
Ubuntu libfreetype6_2.3.5-1ubuntu4.7.10.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6_2. 3.5-1ubuntu4.7.10.1_amd64.deb
Ubuntu Ubuntu Linux 8.04 LTS i386
-
Ubuntu freetype2-demos_2.3.5-1ubuntu4.8.04.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/freetype2-d emos_2.3.5-1ubuntu4.8.04.1_i386.deb -
Ubuntu libfreetype6-dev_2.3.5-1ubuntu4.8.04.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6-de v_2.3.5-1ubuntu4.8.04.1_i386.deb -
Ubuntu libfreetype6-udeb_2.3.5-1ubuntu4.8.04.1_i386.udeb
http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/libfreetype 6-udeb_2.3.5-1ubuntu4.8.04.1_i386.udeb -
Ubuntu libfreetype6_2.3.5-1ubuntu4.8.04.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6_2. 3.5-1ubuntu4.8.04.1_i386.deb
Ubuntu Ubuntu Linux 7.04 powerpc
-
Ubuntu freetype2-demos_2.2.1-5ubuntu1.2_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/freetype2-d emos_2.2.1-5ubuntu1.2_powerpc.deb -
Ubuntu libfreetype6-dev_2.2.1-5ubuntu1.2_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6-de v_2.2.1-5ubuntu1.2_powerpc.deb -
Ubuntu libfreetype6-udeb_2.2.1-5ubuntu1.2_powerpc.udeb
http://security.ubuntu.com/ubuntu/pool/universe/f/freetype/libfreetype 6-udeb_2.2.1-5ubuntu1.2_powerpc.udeb -
Ubuntu libfreetype6_2.2.1-5ubuntu1.2_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/f/freetype/libfreetype6_2. 2.1-5ubuntu1.2_powerpc.deb
FreeType FreeType 2.0.9
-
FreeType ft236.zip
http://download.savannah.gnu.org/releases/freetype/ft236.zip
FreeType FreeType 2.1.7
-
FreeType ft236.zip
http://download.savannah.gnu.org/releases/freetype/ft236.zip
FreeType FreeType 2.3.3
-
FreeType ft236.zip
http://download.savannah.gnu.org/releases/freetype/ft236.zip
FreeType FreeType 2.3.4
-
FreeType ft236.zip
http://download.savannah.gnu.org/releases/freetype/ft236.zip
MandrakeSoft Corporate Server 3.0
-
Mandriva libfreetype6-2.1.7-4.7.C30mdk.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libfreetype6-devel-2.1.7-4.7.C30mdk.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libfreetype6-static-devel-2.1.7-4.7.C30mdk.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva lib64freetype6-2.1.10-9.8.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64freetype6-devel-2.1.10-9.8.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64freetype6-static-devel-2.1.10-9.8.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/
References
FreeType Printer Font Binary Heap Buffer Overflow Vulnerability
References:
References:
- FreeType 2.3.6 Release Notes (FreeType)
- FreeType Homepage (FreeType)
- Multiple Vendor FreeType2 Multiple Heap Overflow Vulnerabilities (iDefense Labs)
- rPath Security Advisory 2008-0255-1 (rPath)
- iDefense Security Advisory 06.10.08: Multiple Vendor FreeType2 Heap Overflow Vul (iDefense Labs
) - ASA-2008-318 - freetype security update (RHSA-2008-0556) (Avaya)
- ASA-2009-226 freetype security update (RHSA-2009-0329) (Avaya)
- RHSA-2008:0556-7 freetype security update (Red Hat)
- RHSA-2008:0556-8 freetype security update (Red Hat)
- RHSA-2008:0558-4 freetype security update (Red Hat)
- RHSA-2008:0558-6 freetype security update (Red Hat)