| Summary: | fontforge new security issues CVE-2017-1156[89], CVE-2017-1157[124567] | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | davidwhodgins, herman.viaene, mageia, rverschelde, sysadmin-bugs |
| Version: | 6 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA5TOO MGA5-32-OK MGA6-64-OK MGA5-64-OK | ||
| Source RPM: | fontforge-20170731-5.mga7.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2017-08-29 22:22:16 CEST
David Walser
2017-08-29 22:23:05 CEST
Whiteboard:
(none) =>
MGA6TOO, MGA5TOO cauldron is not affected Whiteboard:
MGA6TOO, MGA5TOO =>
MGA5TOO Advisory: ======================== Updated fontforge packages fix security vulnerabilities: It was discovered that FontForge, a font editor, did not correctly validate its input. An attacker could use this flaw by tricking a user into opening a maliciously crafted OpenType font file, thus causing a denial-of-service via application crash, or execution of arbitrary code (CVE-2017-11568, CVE-2017-11569, CVE-2017-11571, CVE-2017-11572, CVE-2017-11574, CVE-2017-11575, CVE-2017-11576, CVE-2017-11577). References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11568 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11569 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11571 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11572 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11574 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11575 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11576 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11577 https://www.debian.org/security/2017/dsa-3958 ======================== Updated packages in core/updates_testing: ======================== fontforge-1.0-1.20120731.10.mga5 fontforge-20161012-4.1.mga6 libfontforge-devel-20161012-4.1.mga6 from SRPMS: fontforge-1.0-1.20120731.10.mga5.src.rpm fontforge-20161012-4.1.mga6.src.rpm Assignee:
rverschelde =>
qa-bugs
Dave Hodgins
2018-01-01 07:22:24 CET
CC:
(none) =>
davidwhodgins MGA5-32 on Dell Latitude D600 Xfce No installation issues Ref to bug 3161 Comment 9: Copied LiberationSans_Regular to my home. $ fontforge LiberationSans-Regular.ttf Copyright (c) 2000-2012 by George Williams. Executable based on sources from 14:57 GMT 31-Jul-2012-NoPython. Library based on sources from 14:57 GMT 31-Jul-2012. Rotated uppercase "Gamma" character 90 degrees and followed prompts of editor to save the ttf file. $ fontimage -o fonts.png LiberationSans-Regular.ttf Copyright (c) 2000-2012 by George Williams. Executable based on sources from 14:57 GMT 31-Jul-2012-NoPython. Library based on sources from 14:57 GMT 31-Jul-2012. Checked resulting png file and see rotated character. OK for me. Whiteboard:
MGA5TOO =>
MGA5TOO MGA5-32-OK Validating baesd on fontforge /usr/share/fonts/TTF/liberation/LiberationSans-BoldItalic.ttf working ok. Whiteboard:
MGA5TOO MGA5-32-OK =>
MGA5TOO MGA5-32-OK MGA6-64-OK MGA5-64-OK An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2018-0037.html Resolution:
(none) =>
FIXED |