| MDVSA-2010:235: freetype2 |
|
|
|
| Écrit par Administrator |
| Mardi, 16 Novembre 2010 12:00 |
|
Multiple vulnerabilities were discovered and corrected in freetype2:
An error exists in the "ft_var_readpackedpoints()" function in src/truetype/ttgxvar.c when processing TrueType GX fonts and can be exploited to cause a heap-based buffer overflow via a specially crafted font (CVE-2010-3855). The updated packages have been patched to correct these issues. |



























































