Lucene search

K
amazonAmazonALAS-2013-150
HistoryFeb 03, 2013 - 12:34 p.m.

Important: freetype

2013-02-0312:34:00
alas.aws.amazon.com
17

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

0.015 Low

EPSS

Percentile

86.9%

Issue Overview:

A flaw was found in the way the FreeType font rendering engine processed certain Glyph Bitmap Distribution Format (BDF) fonts. If a user loaded a specially-crafted font file with an application linked against FreeType, it could cause the application to crash or, possibly, execute arbitrary code with the privileges of the user running the application. (CVE-2012-5669)

Affected Packages:

freetype

Issue Correction:
Run yum update freetype to update your system.

New Packages:

i686:  
    freetype-devel-2.3.11-14.13.amzn1.i686  
    freetype-debuginfo-2.3.11-14.13.amzn1.i686  
    freetype-2.3.11-14.13.amzn1.i686  
    freetype-demos-2.3.11-14.13.amzn1.i686  
  
src:  
    freetype-2.3.11-14.13.amzn1.src  
  
x86_64:  
    freetype-devel-2.3.11-14.13.amzn1.x86_64  
    freetype-2.3.11-14.13.amzn1.x86_64  
    freetype-demos-2.3.11-14.13.amzn1.x86_64  
    freetype-debuginfo-2.3.11-14.13.amzn1.x86_64  

Additional References

Red Hat: CVE-2012-5669

Mitre: CVE-2012-5669

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

0.015 Low

EPSS

Percentile

86.9%