Lucene search

K
debianDebianDEBIAN:BSA-078:C9C78
HistoryJan 09, 2013 - 6:28 a.m.

[BSA-078] Security Update for freetype

2013-01-0906:28:35
lists.debian.org
12

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.5 Medium

AI Score

Confidence

Low

0.018 Low

EPSS

Percentile

88.1%

I uploaded new packages for freetype which fixed the
following security problems:

CVE-2012-5668: NULL Pointer Dereference in bdf_free_font.
CVE-2012-5669: Out-of-bounds read in _bdf_parse_glyphs.
CVE-2012-5670: Out-of-bounds write in _bdf_parse_glyphs.

For the squeeze-backports distribution the problems have been fixed in
version 2.4.9-1.1~bpo60+1.

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.5 Medium

AI Score

Confidence

Low

0.018 Low

EPSS

Percentile

88.1%