AnNyung Official Homepage Home > Update [ 1.2 ]  

HOME
What is AnNyung
Documents
Packages System
White Paper
Download
Update
  . 2.x [RSS]
  . 1.3 [RSS]
  . 1.2 [RSS]
  . 1.1 [RSS]
  . 1.0 [RSS]
FAQ
Hardware
RoadMap
Gallery

  Go oops.org
  AnNyung banner 88x31

  AnNyung banner 80x15
  AnNyung banner 80x15
  AnNyung banner 80x15
  AnNyung banner 80x15
  AnNyung banner 80x15
  AnNyung banner 80x15



freetype 보안 업데이트
Web Browser 로는 FTP 접속이 불가능 합니다.

문서번호 : 1153242932
업데이트 : 2006.07.19


상세내용

- CVE-2006-0747

Integer underflow in Freetype before 2.2 allows remote attackers to cause
a denial of service (crash) via a font file with an odd number of blue
values, which causes the underflow when decrementing by 2 in a context
that assumes an even number of values.

- CVE-2006-1861
- CVE-2006-3467

Multiple integer overflows in FreeType before 2.2 allow remote attackers
to cause a denial of service (crash) and possibly execute arbitrary code
via attack vectors related to (1) bdf/bdflib.c, (2) sfnt/ttcmap.c, (3)
cff/cffgload.c, and (4) the read_lwfn function and a crafted LWFN file in
base/ftmac.c. NOTE: item 4 was originally identified by CVE-2006-2493.

- CVE-2006-2661

ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial
of service (crash) via a crafted font file that triggers a null dereference.


Autoupdates 지원 : 지원


update 패키지

  RPMS :

    . freetype-2.1.9-2.i686.rpm
    . freetype-devel-2.1.9-2.i686.rpm

  SRPMS :

    . freetype-2.1.9-2.src.rpm

참고 :
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0747
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1861
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2661
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3467



    



 Home > Update [ 1.2 ]

Copyright 2013 OOPS Development Organization 
LAST MODIFIED: 2013/02/16