~ubuntu-branches/ubuntu/intrepid/freetype/intrepid-security

Viewing all changes in revision 20.

  • Committer: Bazaar Package Importer
  • Author(s): Marc Deslauriers
  • Date: 2009-04-22 09:41:39 UTC
  • Revision ID: james.westby@ubuntu.com-20090422094139-5460n20y5ybiy0pi
Tags: 2.3.7-2ubuntu1.1
* SECURITY UPDATE: possible code execution via multiple integer overflows
  - debian/patches-freetype/security-CVE-2009-0946.patch: validate sid
    values in src/cff/cffload.c, check state->prefix in src/lzw/ftzopen.c,
    don't overflow int with table + length or ndp + numMappings * 4 in
    src/sfnt/ttcmap.c, validate glyph width and height in
    src/smooth/ftsmooth.c.
  - CVE-2009-0946

expand all expand all

Show diffs side-by-side

added added

removed removed

Lines of Context: