Contact | Site en Français               

 


 

Vulnerabilities & Threats

 
  VUPEN Security Advisories
  Linux Security Advisories

  Malware Advisories

  Security Research
  Threat Watch Blog
  Zero-Day Monitor
  Search Engine
  Mailing List & RSS
 
   

>> Fedora Security Update Fixes FreeType "TT_Load_Simple_Glyph()" Integer Overflow

Title : Fedora Security Update Fixes FreeType "TT_Load_Simple_Glyph()" Integer Overflow
VUPEN ID : VUPEN/ADV-2007-2275
CVE ID : CVE-2007-2754
Rated as : Moderate Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2007-06-21


Technical Description    Receive VUPEN Security alerts in a Text format  Receive VUPEN Security alerts in a PDF format  Receive VUPEN Security alerts in an XML format 

A vulnerability has been identified in Fedora, which could be exploited by attackers to execute arbitrary code. This issue is caused by an error in FreeType. For additional information, see : VUPEN/ADV-2007-1894

Affected Products

Fedora Core 6

Solution

Upgrade the affected packages :

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/

d0f7af04140209b4bfa131300aec44a965d49b39 SRPMS/freetype-2.2.1-17.fc6.src.rpm
d0f7af04140209b4bfa131300aec44a965d49b39 noarch/freetype-2.2.1-17.fc6.src.rpm
7954998319a97e2bc5b114ac0ac43667ae3eae78 ppc/freetype-2.2.1-17.fc6.ppc.rpm
40ad4e5df069f0ba67bd90db19096473b5627d73 ppc/freetype-devel-2.2.1-17.fc6.ppc.rpm
7a52b31d200af533a6272fd9e22d0aa751a763c7 ppc/debug/freetype-debuginfo-2.2.1-17.fc6.ppc.rpm
d15dbc6d9c6f0a8b370d4cb9f63e3153b2cfe5d7 ppc/freetype-demos-2.2.1-17.fc6.ppc.rpm
06d3bec1c773e05bbe7abd816c32cdd791de993e x86_64/freetype-2.2.1-17.fc6.x86_64.rpm
ada8c03f21e7a7ddc64536fb9d2739d1ba61e230 x86_64/freetype-demos-2.2.1-17.fc6.x86_64.rpm
3c6a99f0658829d388d76408eaf8b6937aed1240 x86_64/debug/freetype-debuginfo-2.2.1-17.fc6.x86_64.rpm
4aa03d427aaa294c0b84a84d4e635eff27bb2d4f x86_64/freetype-devel-2.2.1-17.fc6.x86_64.rpm
eae444a9bac1b29af790accff575ef1b85b5e809 i386/freetype-demos-2.2.1-17.fc6.i386.rpm
a0474faf94851a07221acdf1066278e8f9e0a3ab i386/debug/freetype-debuginfo-2.2.1-17.fc6.i386.rpm
bab66d3f8614af702fc428097489ee85b698a8ca i386/freetype-2.2.1-17.fc6.i386.rpm
ad982c114fc207d58ce3f3d0ade09e1aa150e709 i386/freetype-devel-2.2.1-17.fc6.i386.rpm

References

http://www.vupen.com/english/advisories/2007/2275
https://www.redhat.com/archives/fedora-package-announce/2007-June/msg00406.html

ChangeLog

2007-06-21 : Initial release

Vulnerability Management

Subscribe to VUPEN VNS and receive real-time alerts when new advisories or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form.

 

Vulnerability Alerting

Free 14-Day Trial

 
  Latest News

 

  >> 2009-07-06

     

  Microsoft Windows 0-Day
  Flaw Exploited in the Wild


  >> 2009-06-10

     

  VUPEN Security Research
  Discovered Critical Flaws
  in Adobe Acrobat and MS

  Office Word


  >> 2009-06-02

     

  VUPEN Security Research
  Discovered Critical Flaws
  in ACDSee Products


  >> 2009-05-22

     

  VUPEN Discovered Two
  Critical Vulnerabilities in
  Novell GroupWise 8 / 7

 

 

More Informations    
    








Copyright 2003-2009 © VUPEN.COM - Privacy Policy