Articles / Debian: New freetype packag…

Debian: New freetype packages fix execution of arbitrary code

It was discovered that an integer overflow in freetype's PCF font code may lead to denial of service and potential execution of arbitrary code. Fixed packages are available from
Debian Security Advisory DSA 1178-1                                   Moritz Muehlenhoff
September 16th, 2006          
Package        : freetype
Vulnerability  : integer overflow
Problem-Type   : local(remote)
Debian-specific: no
CVE ID         : CVE-2006-3467
Debian Bug     : 379920

It was discovered that an integer overflow in freetype's PCF font code
may lead to denial of service and potential execution of arbitrary code.

For the stable distribution (sarge) this problem has been fixed in
version 2.1.7-6.

For the unstable distribution (sid) this problem has been fixed in
version 2.2.1-5.

We recommend that you upgrade your freetype package.

Upgrade Instructions
wget url
       will fetch the file for you
dpkg -i file.deb
       will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
       will update the internal database
apt-get upgrade
       will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge
 These files will probably be moved into the stable distribution on
 its next update.

For apt-get: deb stable/updates main
For dpkg-ftp: dists/stable/updates/main
Mailing list:
Package info: `apt-cache show ' and
