|
|
>> Fedora Security Update Fixes FreeType "TT_Load_Simple_Glyph()" Integer Overflow
|
Title : Fedora Security Update Fixes FreeType "TT_Load_Simple_Glyph()" Integer Overflow VUPEN ID : VUPEN/ADV-2007-2275 CVE ID : CVE-2007-2754
Rated as : Moderate Risk 
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-06-21
|
A vulnerability has been identified in Fedora, which could be exploited by attackers to execute arbitrary code. This issue is caused by an error in FreeType. For additional information, see : VUPEN/ADV-2007-1894
Affected Products
Fedora Core 6
Solution
Upgrade the affected packages :
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
d0f7af04140209b4bfa131300aec44a965d49b39 SRPMS/freetype-2.2.1-17.fc6.src.rpm
d0f7af04140209b4bfa131300aec44a965d49b39 noarch/freetype-2.2.1-17.fc6.src.rpm
7954998319a97e2bc5b114ac0ac43667ae3eae78 ppc/freetype-2.2.1-17.fc6.ppc.rpm
40ad4e5df069f0ba67bd90db19096473b5627d73 ppc/freetype-devel-2.2.1-17.fc6.ppc.rpm
7a52b31d200af533a6272fd9e22d0aa751a763c7 ppc/debug/freetype-debuginfo-2.2.1-17.fc6.ppc.rpm
d15dbc6d9c6f0a8b370d4cb9f63e3153b2cfe5d7 ppc/freetype-demos-2.2.1-17.fc6.ppc.rpm
06d3bec1c773e05bbe7abd816c32cdd791de993e x86_64/freetype-2.2.1-17.fc6.x86_64.rpm
ada8c03f21e7a7ddc64536fb9d2739d1ba61e230 x86_64/freetype-demos-2.2.1-17.fc6.x86_64.rpm
3c6a99f0658829d388d76408eaf8b6937aed1240 x86_64/debug/freetype-debuginfo-2.2.1-17.fc6.x86_64.rpm
4aa03d427aaa294c0b84a84d4e635eff27bb2d4f x86_64/freetype-devel-2.2.1-17.fc6.x86_64.rpm
eae444a9bac1b29af790accff575ef1b85b5e809 i386/freetype-demos-2.2.1-17.fc6.i386.rpm
a0474faf94851a07221acdf1066278e8f9e0a3ab i386/debug/freetype-debuginfo-2.2.1-17.fc6.i386.rpm
bab66d3f8614af702fc428097489ee85b698a8ca i386/freetype-2.2.1-17.fc6.i386.rpm
ad982c114fc207d58ce3f3d0ade09e1aa150e709 i386/freetype-devel-2.2.1-17.fc6.i386.rpm
References
http://www.vupen.com/english/advisories/2007/2275 https://www.redhat.com/archives/fedora-package-announce/2007-June/msg00406.html
ChangeLog
2007-06-21 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|