Submitted by MarcDeslauriers on Mon, 2009-04-27 21:31
Referenced CVEs:
CVE-2009-0946
Description:
===========================================================
Ubuntu Security Notice USN-767-1 April 27, 2009
freetype vulnerability
CVE-2009-0946
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libfreetype6 2.1.10-1ubuntu2.6
Ubuntu 8.04 LTS:
libfreetype6 2.3.5-1ubuntu4.8.04.2
Ubuntu 8.10:
libfreetype6 2.3.7-2ubuntu1.1
Ubuntu 9.04:
libfreetype6 2.3.9-4ubuntu0.1
After a standard system upgrade you need to restart your session to effect
the necessary changes.
Details follow:
Tavis Ormandy discovered that FreeType did not correctly handle certain
large values in font files. If a user were tricked into using a specially
crafted font file, a remote attacker could execute arbitrary code with user
privileges.


