Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 1635-1] New freetype packages fix multiple vulnerabilit

    From Steve Kemp@1:229/2 to All on Wed Sep 10 22:10:17 2008
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-1635-1 [email protected] http://www.debian.org/security/ Steve Kemp September 10, 2008 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : freetype
    Vulnerability : multiple
    Problem type : local
    Debian-specific: no
    CVE Id(s) : CVE-2008-1806 CVE-2008-1807 CVE-2008-1808

    Several local vulnerabilities have been discovered in freetype,
    a FreeType 2 font engine, which could allow the execution of arbitrary
    code.

    The Common Vulnerabilities and Exposures project identifies the
    following problems:

    CVE-2008-1806
    An integer overflow allows context-dependent attackers to execute
    arbitrary code via a crafted set of values within the Private
    dictionary table in a Printer Font Binary (PFB) file.

    CVE-2008-1807
    The handling of an invalid "number of axes" field in the PFB file could
    trigger the freeing of aribtrary memory locations, leading to
    memory corruption.

    CVE-2008-1808
    Multiple off-by-one errors allowed the execution of arbitrary code
    via malformed tables in PFB files, or invalid SHC instructions in
    TTF files.


    For the stable distribution (etch), these problems have been fixed in version 2.2.1-5+etch3.

    For the unstable distribution (sid), these problems have been fixed in
    version 2.3.6-1.

    We recommend that you upgrade your freetype package.


    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 4.0 alias etch
    - -------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/f/freetype/freetype_2.2.1-5+etch3.diff.gz
    Size/MD5 checksum: 33815 16f3a9f45c8ba0743fcce4db637b11bf
    http://security.debian.org/pool/updates/main/f/freetype/freetype_2.2.1-5+etch3.dsc
    Size/MD5 checksum: 806 5a9af398d4749d9b1da47b6d9dbab821

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/f/freetype/freetype2-demos_2.2.1-5+etch3_alpha.deb
    Size/MD5 checksum: 169018 c99046707c48ee95504b3584e3acaffa
    http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-dev_2.2.1-5+etch3_alpha.deb
    Size/MD5 checksum: 733276 3db91ded5b0de609d968ab8e53920289
    http://security.debian.org/pool/updates/main/f/freetype/libfreetype6_2.2.1-5+etch3_alpha.deb
    Size/MD5 checksum: 386320 bf7f4273b546ef4826416b2b33e4f94a
    http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-udeb_2.2.1-5+etch3_alpha.udeb
    Size/MD5 checksum: 279290 57b6163945dcedbc6269f4a9779c0fd1

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-dev_2.2.1-5+etch3_amd64.deb
    Size/MD5 checksum: 673858 0501dce4dff1621ecee0e2ce3eaef4aa
    http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-udeb_2.2.1-5+etch3_amd64.udeb
    Size/MD5 checksum: 248168 9b5d402a5937e847a5e950384421d86c
    http://security.debian.org/pool/updates/main/f/freetype/freetype2-demos_2.2.1-5+etch3_amd64.deb
    Size/MD5 checksum: 151546 2a6ff47137700ff8730440ccd7f7d151
    http://security.debian.org/pool/updates/main/f/freetype/libfreetype6_2.2.1-5+etch3_amd64.deb
    Size/MD5 checksum: 355500 87b2fb3932e86863c46c74916c1a5dde

    arm architecture (ARM)

    http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-dev_2.2.1-5+etch3_arm.deb
    Size/MD5 checksum: 646720 cd1705ecfef442f90d80e1fb83db292c
    http://security.debian.org/pool/updates/main/f/freetype/libfreetype6_2.2.1-5+etch3_arm.deb
    Size/MD5 checksum: 333838 060a4e7f6977045c5d7f35a721edc041
    http://security.debian.org/pool/updates/main/f/freetype/freetype2-demos_2.2.1-5+etch3_arm.deb
    Size/MD5 checksum: 134028 e6dcac8b5abd633c83547bd34515dd82
    http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-udeb_2.2.1-5+etch3_arm.udeb
    Size/MD5 checksum: 227294 41c45c91535b5325ae06649a1e4a3b1c

    hppa architecture (HP PA RISC)

    http://security.debian.org/pool/updates/main/f/freetype/libfreetype6_2.2.1-5+etch3_hppa.deb
    Size/MD5 checksum: 369068 3bcfc3bbe665b9aae3b3933b25a04661
    http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-udeb_2.2.1-5+etch3_hppa.udeb
    Size/MD5 checksum: 260548 5cc41d234eea28201f11485b610fb046
    http://security.debian.org/pool/updates/main/f/freetype/freetype2-demos_2.2.1-5+etch3_hppa.deb
    Size/MD5 checksum: 151538 3aa7946fc0b6efb9057d108b37389640
    http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-dev_2.2.1-5+etch3_hppa.deb
    Size/MD5 checksum: 685988 1220846ff1f3409afc9c3ad873954315

    i386 architecture (Intel ia32)

    http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-dev_2.2.1-5+etch3_i386.deb
    Size/MD5 checksum: 645534 ccaaafcb5eda1820727ddcf67550a9c6
    http://security.debian.org/pool/updates/main/f/freetype/libfreetype6_2.2.1-5+etch3_i386.deb
    Size/MD5 checksum: 342704 9b65398aaaf701879d4106fbc7c1b241
    http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-udeb_2.2.1-5+etch3_i386.udeb
    Size/MD5 checksum: 235954 67dc56faf0a5683f42723ceaaff13617
    http://security.debian.org/pool/updates/main/f/freetype/freetype2-demos_2.2.1-5+etch3_i386.deb
    Size/MD5 checksum: 134990 739490a353dbb1b5a09a7a88faa2d2c2

    ia64 architecture (Intel ia64)

    http://security.debian.org/pool/updates/main/f/freetype/libfreetype6-udeb_2.2.1-5+etch3_ia64.udeb
    Size/MD5 checksum: 383448 0b7a52c014942c4f2b917a6bdb86c404
    http://security.debian.org/pool/updates/main/f/freetype/freetype2-demos_2.2.1-5+etch3_ia64.deb
    Size/MD5 checksum: 222240 3f474395622187bb18adfc1a4bac738d

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Krenn
      Sun Jun 7 03:07:26 2026
      from Sydney, Nsw via Telnet
    • Krenn
      Sun Jun 7 01:30:12 2026
      from Sydney, Nsw via Telnet
    • Centurion
      Sat Jun 6 23:27:30 2026
      from Berea, Ohio via Telnet
    • Ab Cadd
      Sat Jun 6 15:42:53 2026
      from Sheboygan, Wi via Telnet
    • Centurion
      Sat Jun 6 15:32:28 2026
      from Berea, Ohio via Telnet
    • Krenn
      Sat Jun 6 11:38:56 2026
      from Sydney, Nsw via Telnet
    • Furryboy
      Sat Jun 6 10:56:29 2026
      from Romania, Galati via SSH
    • Centurion
      Fri Jun 5 22:28:01 2026
      from Berea, Ohio via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 158:55:31
    Calls: 12,094
    Calls today: 2
    Files: 15,000
    Messages: 6,517,759

© >>> Magnum BBS <<<, 2026