Debian Security Advisory

DSA-3188-1 freetype -- security update

Date Reported:
15 Mar 2015
Affected Packages:
freetype
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2014-9656, CVE-2014-9657, CVE-2014-9658, CVE-2014-9660, CVE-2014-9661, CVE-2014-9663, CVE-2014-9664, CVE-2014-9666, CVE-2014-9667, CVE-2014-9669, CVE-2014-9670, CVE-2014-9671, CVE-2014-9672, CVE-2014-9673, CVE-2014-9675.
More information:

Mateusz Jurczyk discovered multiple vulnerabilities in Freetype. Opening malformed fonts may result in denial of service or the execution of arbitrary code.

For the stable distribution (wheezy), these problems have been fixed in version 2.4.9-1.1+deb7u1.

For the upcoming stable distribution (jessie), these problems have been fixed in version 2.5.2-3.

For the unstable distribution (sid), these problems have been fixed in version 2.5.2-3.

We recommend that you upgrade your freetype packages.