SB2014021106 - Gentoo update for FreeType
Published: February 11, 2014 Updated: September 25, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) NULL pointer dereference (CVE-ID: CVE-2012-5668)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error. A remote attacker can trigger denial of service conditions via vectors related to BDF fonts and the improper handling of an "allocation error" in the bdf_free_font function.
2) Buffer overflow (CVE-ID: CVE-2012-5669)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to BDF fonts and an incorrect calculation that triggers an out-of-bounds read.
3) Buffer overflow (CVE-ID: CVE-2012-5670)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) via vectors related to BDF fonts and an ENCODING field with a negative value.
Remediation
Install update from vendor's website.