• [SECURITY] [DSA 3839-1] freetype security update

    From Salvatore Bonaccorso@1:229/2 to All on Fri Apr 28 21:30:02 2017
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3839-1 [email protected] https://www.debian.org/security/ Salvatore Bonaccorso
    April 28, 2017 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : freetype
    CVE ID : CVE-2016-10244 CVE-2017-8105 CVE-2017-8287
    Debian Bug : 856971 861220 861308

    Several vulnerabilities were discovered in Freetype. Opening malformed
    fonts may result in denial of service or the execution of arbitrary
    code.

    For the stable distribution (jessie), these problems have been fixed in
    version 2.5.2-3+deb8u2.

    We recommend that you upgrade your freetype packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAlkDlu9fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0RFsw//V/8JhFN4WoFeMiB+7F59yz82zkAUV6ik8H4XOorHaVyvGOqYj2Tp+spz 5dK90pby30p/ALEVriSEt8/bLMnJVVeX4D8RCR+SurRHTa10JX13Hq+ik9fGfnke Lue6TEKkkVdOW0XHiO9tmXs9ADztg/3PwwFSsKaShP61Bsu+f+d9QUCC6Rkgwt0A 21h3m3+rDBJ4Q3AT2yslW+hMR5ib2b5J5BxsWy9Xltu7FBEVHrUnyGmAeb+JgmEH usnzmPh+tb7tCCFuWOkjONOBGkoxgxa3HeJ2zjOrQGdBP8MlN+TAfTFBIvWd8VB+ VWoDMw/Dsjbu2SbR5+nGvAk06yecBV9tqjAfmiX5F4kkF91Y4oCA6g1+5MP4ENLU AyRqJaaccspxPP7P3JIqQYgVsi1IjVtGkmqL+7bic/DbmF08GEMKSGLkDsVthpCl I2F3NDQppeXRSenZ94Qow5vfS+5nBDnqh9eui20SfJMWWy7IVwNOCix4IPdJNW0n e1/pKGStZQOl5PaxACIdJp1O2zPhefMj+fQZjz6ZSZxcJ6SqqCqshHhlULutzYix tTDWE/aj8Re9LBF6+ouCyW56U3Z14cb71xvYtfDBp3hhkHsVmAwxrMS+/iQupA+a 3iOHgJ5WtHhqkz0Bz6SmV8UsFHfbL7fitnYLI22Auq0fJk7ODjY=
    =fFNT
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)