Bug#741299: freetype: CVE-2014-2240, CVE-2014-2241: stack OOB read/write, DoS

2014-08-09 Thread Michael Gilbert
control: tag -1 patch Hi, I've uploaded an nmu fixing this issue. Please see attached patch. Best wishes, Mike diff -u freetype-2.5.2/debian/changelog freetype-2.5.2/debian/changelog --- freetype-2.5.2/debian/changelog +++ freetype-2.5.2/debian/changelog @@ -1,3 +1,12 @@ +freetype (2.5.2-1.1)

Bug#741299: freetype: CVE-2014-2240, CVE-2014-2241: stack OOB read/write, DoS

2014-03-10 Thread Raphael Geissert
Source: freetype Version: 2.5.1-1 Severity: grave Tags: patch Hi, Two vulnerabilities have been identified in freetype in the recently contributed CFF rasterizer code. Please refer to the references for the details. From what I understood from the bug report, CVE-2014-2240 is the stack OOB