Oval Definition:oval:com.redhat.rhsa:def:20080556
Revision Date:2008-06-25Version:641
Title:RHSA-2008:0556: freetype security update (Important)
Description:FreeType is a free, high-quality, portable font engine that can open and manage font files, as well as efficiently load, hint and render individual glyphs.

  • Multiple flaws were discovered in FreeType's Printer Font Binary (PFB) font-file format parser. If a user loaded a carefully crafted font-file with a program linked against FreeType, it could cause the application to crash, or possibly execute arbitrary code. (CVE-2008-1806, CVE-2008-1807, CVE-2008-1808)

    Note: the flaw in FreeType's TrueType Font (TTF) font-file format parser, covered by CVE-2008-1808, did not affect the freetype packages as shipped in Red Hat Enterprise Linux 3, 4, and 5, as they are not compiled with TTF Byte Code Interpreter (BCI) support.

    Users of freetype should upgrade to these updated packages, which contain backported patches to resolve these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2008-1806
    CVE-2008-1807
    CVE-2008-1808
    RHSA-2008:0556
    RHSA-2008:0556-02
    RHSA-2008:0556-02
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • freetype-devel is earlier than 0:2.1.4-10.el3
  • AND freetype-devel is signed with Red Hat master key
  • freetype is earlier than 0:2.1.4-10.el3
  • AND freetype is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • freetype-devel is earlier than 0:2.1.9-8.el4.6
  • AND freetype-devel is signed with Red Hat master key
  • freetype-demos is earlier than 0:2.1.9-8.el4.6
  • AND freetype-demos is signed with Red Hat master key
  • freetype is earlier than 0:2.1.9-8.el4.6
  • AND freetype is signed with Red Hat master key
  • freetype-utils is earlier than 0:2.1.9-8.el4.6
  • AND freetype-utils is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • freetype-demos is earlier than 0:2.2.1-20.el5_2
  • AND freetype-demos is signed with Red Hat redhatrelease key
  • freetype-devel is earlier than 0:2.2.1-20.el5_2
  • AND freetype-devel is signed with Red Hat redhatrelease key
  • freetype is earlier than 0:2.2.1-20.el5_2
  • AND freetype is signed with Red Hat redhatrelease key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • freetype is earlier than 0:2.1.9-8.el4.6
  • AND freetype is signed with Red Hat redhatrelease2 key
  • freetype-demos is earlier than 0:2.1.9-8.el4.6
  • AND freetype-demos is signed with Red Hat redhatrelease2 key
  • freetype-devel is earlier than 0:2.1.9-8.el4.6
  • AND freetype-devel is signed with Red Hat redhatrelease2 key
  • freetype-utils is earlier than 0:2.1.9-8.el4.6
  • AND freetype-utils is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • freetype is earlier than 0:2.2.1-20.el5_2
  • AND freetype is signed with Red Hat redhatrelease2 key
  • freetype-demos is earlier than 0:2.2.1-20.el5_2
  • AND freetype-demos is signed with Red Hat redhatrelease2 key
  • freetype-devel is earlier than 0:2.2.1-20.el5_2
  • AND freetype-devel is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • freetype is earlier than 0:2.1.4-10.el3
  • AND freetype is signed with Red Hat master key
  • freetype-demos is earlier than 0:2.1.4-10.el3
  • AND freetype-demos is signed with Red Hat master key
  • freetype-devel is earlier than 0:2.1.4-10.el3
  • AND freetype-devel is signed with Red Hat master key
  • freetype-utils is earlier than 0:2.1.4-10.el3
  • AND freetype-utils is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • freetype is earlier than 0:2.1.9-8.el4.6
  • AND freetype is signed with Red Hat master key
  • freetype-demos is earlier than 0:2.1.9-8.el4.6
  • AND freetype-demos is signed with Red Hat master key
  • freetype-devel is earlier than 0:2.1.9-8.el4.6
  • AND freetype-devel is signed with Red Hat master key
  • freetype-utils is earlier than 0:2.1.9-8.el4.6
  • AND freetype-utils is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • freetype is earlier than 0:2.2.1-20.el5_2
  • AND freetype is signed with Red Hat redhatrelease key
  • freetype-demos is earlier than 0:2.2.1-20.el5_2
  • AND freetype-demos is signed with Red Hat redhatrelease key
  • freetype-devel is earlier than 0:2.2.1-20.el5_2
  • AND freetype-devel is signed with Red Hat redhatrelease key
  • BACK