- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Hugh McMaster
- Date:
- 2022-07-09 10:52:12 UTC
- Severity:
- normal
- Tags:
This update fixes three security vulnerabilities in FreeType 2.10.4+dfsg-1. - CVE-2022-27404: heap buffer overflow via invalid integer decrement in sfnt_init_face() and woff2_open_font(). - CVE-2022-27405: segmentation violation via ft_open_face_internal() when attempting to read the value of FT_LONG face_index. - CVE-2022-27406: segmentation violation via FT_Request_Size() when attempting to read the value of an unguarded face size handle. It would be ideal to get these fixes into Bullseye.
Control: tags -1 + confirmed d-i This looks OK to me, but as freetype builds a udeb it will want a KiBi- ack; CCed and tagging accordingly. Regards, Adam
Hi Adam, Thanks for the ack. I've been waiting for KiBi, but just wanted to check whether I'm supposed to upload before that happens. Hugh
package release.debian.org tags 1010304 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: freetype Version: 2.10.4+dfsg-1+deb11u1 Explanation: fix buffer overflow issue [CVE-2022-27404]; fix crashes [CVE-2022-27405 CVE-2022-27406]
package release.debian.org tags 1010304 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: freetype Version: 2.10.4+dfsg-1+deb11u1 Explanation: fix buffer overflow issue [CVE-2022-27404]; fix crashes [CVE-2022-27405 CVE-2022-27406]
(re-sending with fixed bug numbers) Hi, The updates discussed in these bugs were included in today's bullseye point release. Regards, Adam