Source: freetype
Version: 2.11.1+dfsg-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for freetype.

CVE-2022-27404[0]:
| FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was
| discovered to contain a heap buffer overflow via the function
| sfnt_init_face.


CVE-2022-27405[1]:
| FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was
| discovered to contain a segmentation violation via the function
| FNT_Size_Request.


CVE-2022-27406[2]:
| FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was
| discovered to contain a segmentation violation via the function
| FT_Request_Size.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2022-27404
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27404
[1] https://security-tracker.debian.org/tracker/CVE-2022-27405
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27405
[2] https://security-tracker.debian.org/tracker/CVE-2022-27406
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27406

Regards,
Salvatore

Reply via email to