Univention Bugzilla – Bug 52267
freetype: Multiple issues (4.4)
Last modified: 2020-10-28 12:49:27 CET
New Debian freetype 2.6.3-3.2+deb9u2 fixes: This update addresses the following issue: * Heap-based buffer overflow due to integer truncation in Load_SBit_Png (CVE-2020-15999)
--- mirror/ftp/4.4/unmaintained/4.4-4/source/freetype_2.6.3-3.2+deb9u1.dsc +++ apt/ucs_4.4-0-errata4.4-6/source/freetype_2.6.3-3.2+deb9u2.dsc @@ -1,3 +1,9 @@ +2.6.3-3.2+deb9u2 [Fri, 23 Oct 2020 19:03:02 +0200] Thorsten Alteholz <debian@alteholz.de>: + + * Non-maintainer upload by the LTS Team. + * CVE-2020-15999 + Fix heap buffer overflow. + 2.6.3-3.2+deb9u1 [Sun, 28 Jul 2019 19:35:12 +1000] Hugh McMaster <hugh.mcmaster@outlook.com>: * Add an upstream patch to correctly handle deltas in TrueType GX fonts <http://10.200.17.11/4.4-6/#8280588230679444758>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-6] b73f7ee513 Bug #52267: freetype 2.6.3-3.2+deb9u2 doc/errata/staging/freetype.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+)
<https://errata.software-univention.de/#/?erratum=4.4x783>