#1010304 bullseye-pu: package freetype/2.10.4+dfsg-1+deb11u1

#1010304#5
Date:
2022-04-28 12:21:20 UTC
From:
To:
This update fixes three security vulnerabilities in FreeType 2.10.4+dfsg-1.

- CVE-2022-27404: heap buffer overflow via invalid integer decrement in
sfnt_init_face() and woff2_open_font().
- CVE-2022-27405: segmentation violation via ft_open_face_internal() when
attempting to read the value of FT_LONG face_index.
- CVE-2022-27406: segmentation violation via FT_Request_Size() when attempting
to read the value of an unguarded face size handle.

It would be ideal to get these fixes into Bullseye.

#1010304#10
Date:
2022-05-28 19:15:38 UTC
From:
To:
Control: tags -1 + confirmed d-i

This looks OK to me, but as freetype builds a udeb it will want a KiBi-
ack; CCed and tagging accordingly.

Regards,

Adam

#1010304#17
Date:
2022-06-13 12:02:14 UTC
From:
To:
Hi Adam,

Thanks for the ack. I've been waiting for KiBi, but just wanted to
check whether I'm supposed to upload before that happens.

Hugh

#1010304#22
Date:
2022-07-01 15:23:01 UTC
From:
To:
package release.debian.org
tags 1010304 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==============

Package: freetype
Version: 2.10.4+dfsg-1+deb11u1

Explanation: fix buffer overflow issue [CVE-2022-27404]; fix crashes [CVE-2022-27405 CVE-2022-27406]

#1010304#27
Date:
2022-07-01 15:23:01 UTC
From:
To:
package release.debian.org
tags 1010304 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==============

Package: freetype
Version: 2.10.4+dfsg-1+deb11u1

Explanation: fix buffer overflow issue [CVE-2022-27404]; fix crashes [CVE-2022-27405 CVE-2022-27406]

#1010304#32
Date:
2022-07-09 10:47:43 UTC
From:
To:
(re-sending with fixed bug numbers)

Hi,

The updates discussed in these bugs were included in today's bullseye
point release.

Regards,

Adam