Debian Security Advisory

DLA-848-1 freetype -- LTS security update

Date Reported:
07 Mar 2017
Affected Packages:
freetype
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2016-10244.
More information:

It was discovered that there was a denial of service vulnerability in freetype, a font rendering library.

The parse_charstrings function did not ensure that a font contains a glyph name, which allowed remote attackers to cause a denial of service via a specially-crafted file.

For Debian 7 Wheezy, this issue has been fixed in freetype version 2.4.9-1.1+deb7u4.

We recommend that you upgrade your freetype packages.