May 22, 2012, 10:03:24 PM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: THC is up and running !
 

 
advertisement:

Pages: [1]
  Print  
Author Topic: USN767-1 : freetype vulnerability  (Read 68 times)
zomgwtfbbq
Challenge Coder
Administrator
Hero Member
*****

Karma: +31340/-1
Posts: I am a geek!!


thc title: thc elite
thc points: 3315
challenges: (69/83)

View Profile
« on: April 28, 2009, 10:59:10 AM »
Share on FacebookFacebook Share

Synopsis :

These remote packages are missing security patches :
- freetype2-demos
- libfreetype6
- libfreetype6-dev

Description :

Tavis Ormandy discovered that FreeType did not correctly handle certain
large values in font files. If a user were tricked into using a specially
crafted font file, a remote attacker could execute arbitrary code with user
privileges.

Solution :

Upgrade to :
- freetype2-demos-2.3.9-4ubuntu0.1 (Ubuntu 9.04)
- libfreetype6-2.3.9-4ubuntu0.1 (Ubuntu 9.04)
- libfreetype6-dev-2.3.9-4ubuntu0.1 (Ubuntu 9.04)

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)



only registered users with at least 25 hack challenge points can see links:
  click here in order to visit the hack challenges
More...
Logged


only registered users with at least 25 hack challenge points can see links:
  click here in order to visit the hack challenges


Ook al ben ik een slet toch houdt ik van je..
Pages: [1]
  Print  
 
Jump to:  


SMF Board hacked and modded by zomgwtfbekjam aka Rembo from Tools & Design