Bug 3349 - Updated freetype2 package to fix CVE-2011-3439
Summary: Updated freetype2 package to fix CVE-2011-3439
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 1
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL: http://sourceforge.net/projects/freet...
Whiteboard:
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2011-11-15 14:37 CET by Funda Wang
Modified: 2011-12-03 21:22 CET (History)
4 users (show)

See Also:
Source RPM: freetype2-2.4.4-5.4.mga1
CVE:
Status comment:


Attachments

Description Funda Wang 2011-11-15 14:37:17 CET
Some vulnerabilities in handling CID-keyed PostScript fonts have been found in freetype2 (CVE-2011-3439).

The updated packages have been patched to fix this issue.
Comment 1 Funda Wang 2011-11-15 14:38:24 CET
@qateam,

please see that freetype2 existing in both core and tainted.
Comment 2 Dave Hodgins 2011-11-19 22:00:35 CET
Testing on i586 complete for the srpm packages
freetype2-2.4.4-5.4.mga1.src.rpm
freetype2-2.4.4-5.4.mga1.tainted.src.rpm

No poc for the vulnerability, so just testing that the packages work.

For testing, I disabled the Tainted updates testing reposiory, and ran
rpm -e --nodeps freetype2-demos libfreetype6 libfreetype6-devel
urpmi freetype2-demos libfreetype6 libfreetype6-devel

which installed the Core Updates Testing packages.  I then confirmed
xpdf could view pdf files.

Enabled the Tainted Updates Testing repository and used
urpmi --auto-select to install the tainted versions of the
packages, and repeated the testing with xpdf.

CC: (none) => davidwhodgins

Comment 3 Derek Jennings 2011-12-01 16:11:46 CET
Validated OK on x86_64

Could someone from sysadmin please push freetype2-2.4.4-5.4.mga1.src.rpm from Core_Updates_Testing to Core_Updates, and push freetype2-2.4.4-5.4.mga1.tainted.src.rpm from Tainted_Updates_testing into Tainted_Updates.

Advisory
--------
This update addresses CVE-2011-3439 which identifies some vulnerabilities in handling CID-keyed PostScript

Keywords: (none) => validated_update
CC: (none) => derekjenn, sysadmin-bugs

Comment 4 Thomas Backlund 2011-12-03 21:22:16 CET
Update pushed.

Status: NEW => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.