Oval Definition:oval:com.redhat.rhsa:def:20162601
Revision Date:2016-11-03Version:639
Title:RHSA-2016:2601: fontconfig security and bug fix update (Moderate)
Description:Fontconfig is designed to locate fonts within the system and select them according to requirements specified by applications.

Security Fix(es):

  • It was found that cache files were insufficiently validated in fontconfig. A local attacker could create a specially crafted cache file to trigger arbitrary free() calls, which in turn could lead to arbitrary code execution. (CVE-2016-5384)

    Red Hat would like to thank Tobias Stoeckmann for reporting this issue.

    Additional Changes:

    For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.3 Release Notes linked from the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2016-5384
    RHSA-2016:2601
    RHSA-2016:2601-01
    RHSA-2016:2601-02
    RHSA-2016:2601-02
    Platform(s):Red Hat Enterprise Linux 7
    Red Hat Enterprise Linux 7 (please do not use for >= RHEL-7.5)
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • fontconfig is earlier than 0:2.10.95-10.el7
  • AND fontconfig is signed with Red Hat redhatrelease2 key
  • fontconfig-devel is earlier than 0:2.10.95-10.el7
  • AND fontconfig-devel is signed with Red Hat redhatrelease2 key
  • fontconfig-devel-doc is earlier than 0:2.10.95-10.el7
  • AND fontconfig-devel-doc is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 7 Client is installed
  • OR Red Hat Enterprise Linux 7 Server is installed
  • OR Red Hat Enterprise Linux 7 Workstation is installed
  • OR Red Hat Enterprise Linux 7 ComputeNode is installed
  • AND Package Information
  • fontconfig-devel-doc is earlier than 0:2.10.95-10.el7
  • AND fontconfig-devel-doc is signed with Red Hat redhatrelease2 key
  • OR
  • fontconfig is earlier than 0:2.10.95-10.el7
  • AND fontconfig is signed with Red Hat redhatrelease2 key
  • OR
  • fontconfig-devel is earlier than 0:2.10.95-10.el7
  • AND fontconfig-devel is signed with Red Hat redhatrelease2 key
  • BACK