Oval Definition:oval:com.redhat.rhsa:def:20194254
Revision Date:2019-12-17Version:637
Title:RHSA-2019:4254: freetype security update (Moderate)
Description:FreeType is a free, high-quality, portable font engine that can open and manage font files. FreeType loads, hints, and renders individual glyphs efficiently.

Security Fix(es):

  • freetype: a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c leading to information disclosure (CVE-2015-9381)

  • freetype: mishandling ps_parser_skip_PS_token in an FT_New_Memory_Face operation in skip_comment, psaux/psobjs.c, leads to a buffer over-read (CVE-2015-9382)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2015-9381
    CVE-2015-9382
    RHSA-2019:4254
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • freetype is earlier than 0:2.3.11-19.el6_10
  • AND freetype is signed with Red Hat redhatrelease2 key
  • freetype-demos is earlier than 0:2.3.11-19.el6_10
  • AND freetype-demos is signed with Red Hat redhatrelease2 key
  • freetype-devel is earlier than 0:2.3.11-19.el6_10
  • AND freetype-devel is signed with Red Hat redhatrelease2 key
  • BACK