harfbuzz 2.6.4-1ubuntu4.2 source package in Ubuntu

Changelog

harfbuzz (2.6.4-1ubuntu4.2) focal-security; urgency=medium

  * SECURITY UPDATE: DoS via integer overflow
    - debian/patches/CVE-2022-33068-1.patch: limit glyph extents in
      src/hb-ot-color-sbix-table.hh.
    - debian/patches/CVE-2022-33068-2.patch: fix conditional in
      src/hb-ot-color-sbix-table.hh.
    - CVE-2022-33068
  * debian/rules: increase fuzzer timeouts to fix FTBFS on riscv64.

 -- Marc Deslauriers <email address hidden>  Wed, 13 Jul 2022 12:43:13 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Focal
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
libs
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Focal updates main misc
Focal security main misc

Downloads

File Size SHA-256 Checksum
harfbuzz_2.6.4.orig.tar.xz 5.7 MiB 9413b8d96132d699687ef914ebb8c50440efc87b3f775d25856d7ec347c03c12
harfbuzz_2.6.4-1ubuntu4.2.debian.tar.xz 11.7 KiB d56ad3297b0f8197cdbe4c13785c8e8ee4a863ec3ca069c677e42fda7b0eb324
harfbuzz_2.6.4-1ubuntu4.2.dsc 2.8 KiB a23bda33022c3a54e22296cded64c84d9fe1ce6d089c4a36a66ccb85e326bddc

View changes file

Binary packages built by this source

gir1.2-harfbuzz-0.0: OpenType text shaping engine (GObject introspection data)

 HarfBuzz is an implementation of the OpenType Layout engine (aka layout
 engine) and the script-specific logic (aka shaping engine).
 .
 This package contains introspection data for the GObject bindings library.

libharfbuzz-bin: OpenType text shaping engine (utility)

 HarfBuzz is an implementation of the OpenType Layout engine (aka layout
 engine) and the script-specific logic (aka shaping engine).
 .
 This package contains a command line interface for the HarfBuzz library.

libharfbuzz-bin-dbgsym: debug symbols for libharfbuzz-bin
libharfbuzz-dev: Development files for OpenType text shaping engine

 HarfBuzz is an implementation of the OpenType Layout engine (aka layout
 engine) and the script-specific logic (aka shaping engine).
 .
 This package contains the header files and static libraries for the
 HarfBuzz library.

libharfbuzz-doc: Documentation files for the HarfBuzz library

 HarfBuzz is an implementation of the OpenType Layout engine (aka layout
 engine) and the script-specific logic (aka shaping engine).
 .
 This package contains the HTML documentation for the HarfBuzz library.

libharfbuzz-gobject0: OpenType text shaping engine ICU backend (GObject library)

 HarfBuzz is an implementation of the OpenType Layout engine (aka layout
 engine) and the script-specific logic (aka shaping engine).
 .
 This package contains the GObject library, providing wrapper GObject type
 bindings for all HarfBuzz objects and enums.

libharfbuzz-gobject0-dbgsym: debug symbols for libharfbuzz-gobject0
libharfbuzz-icu0: OpenType text shaping engine ICU backend

 HarfBuzz is an implementation of the OpenType Layout engine (aka layout
 engine) and the script-specific logic (aka shaping engine).
 .
 This package contains the ICU backend.

libharfbuzz-icu0-dbgsym: debug symbols for libharfbuzz-icu0
libharfbuzz0-udeb: OpenType text shaping engine

 HarfBuzz is an implementation of the OpenType Layout engine (aka layout
 engine) and the script-specific logic (aka shaping engine).

libharfbuzz0b: OpenType text shaping engine (shared library)

 HarfBuzz is an implementation of the OpenType Layout engine (aka layout
 engine) and the script-specific logic (aka shaping engine).
 .
 This package contains the shared libraries.

libharfbuzz0b-dbgsym: debug symbols for libharfbuzz0b