Format: 1.7 Date: Fri, 13 Aug 2010 10:55:35 -0400 Source: freetype Binary: freetype2-demos libfreetype6-udeb libfreetype6 libfreetype6-dev Architecture: sparc Version: 2.1.10-1ubuntu2.8 Distribution: dapper Urgency: low Maintainer: Ubuntu/sparc Build Daemon Changed-By: Marc Deslauriers Description: freetype2-demos - FreeType 2 demonstration programs libfreetype6 - FreeType 2 font engine, shared library files libfreetype6-dev - FreeType 2 font engine, development files libfreetype6-udeb - FreeType 2 font engine for the debian-installer (udeb) Changes: freetype (2.1.10-1ubuntu2.8) dapper-security; urgency=low . * SECURITY UPDATE: possible arbitrary code execution via buffer overflow in CFF Type2 CharStrings interpreter (LP: #617019) - debian/patches/418-CVE-2010-1797.patch: check number of operands in src/cff/cffgload.c. - CVE-2010-1797 * SECURITY UPDATE: possible arbitrary code execution via buffer overflow in the ftmulti demo program (LP: #617019) - debian/patches/424-CVE-2010-2541.patch: use strncat and adjust sizes in src/ftmulti.c. - CVE-2010-2541 * SECURITY UPDATE: possible arbitrary code execution via improper bounds checking (LP: #617019) - debian/patches/419-CVE-2010-2805.patch: fix calculation in src/base/ftstream.c. - CVE-2010-2805 * SECURITY UPDATE: possible arbitrary code execution via improper bounds checking (LP: #617019) - debian/patches/420-CVE-2010-2806.patch: check string sizes in src/type42/t42parse.c. - CVE-2010-2806 * SECURITY UPDATE: possible arbitrary code execution via improper type comparisons (LP: #617019) - debian/patches/421-CVE-2010-2807.patch: perform better bounds checking in src/smooth/ftsmooth.c, src/truetype/ttinterp.*. - CVE-2010-2807 * SECURITY UPDATE: possible arbitrary code execution via memory corruption in Adobe Type 1 Mac Font File (LWFN) fonts (LP: #617019) - debian/patches/422-CVE-2010-2808.patch: check rlen in src/base/ftobjs.c. - CVE-2010-2808 * SECURITY UPDATE: denial of service via bdf font (LP: #617019) - debian/patches/423-bug30135.patch: don't modify value in static string in src/bdf/bdflib.c. Files: efaca20d5deec9e51be023710902852b 411982 libs optional libfreetype6_2.1.10-1ubuntu2.8_sparc.deb 49df9101deb9a317229351d72b5804ec 683964 libdevel optional libfreetype6-dev_2.1.10-1ubuntu2.8_sparc.deb ff723720ed499e40049e3487844b9db3 120138 utils optional freetype2-demos_2.1.10-1ubuntu2.8_sparc.deb 71f172ba71fc507b04e5337d55b32ed6 222676 debian-installer extra libfreetype6-udeb_2.1.10-1ubuntu2.8_sparc.udeb