Mandrake Linux Security Advisory : freetype2 (MDKSA-2006:099-1)

high Nessus Plugin ID 21715

Synopsis

The remote Mandrake Linux host is missing one or more security updates.

Description

Integer underflow in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a font file with an odd number of blue values, which causes the underflow when decrementing by 2 in a context that assumes an even number of values. (CVE-2006-0747)

Multiple integer overflows in FreeType before 2.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to (1) bdf/bdflib.c, (2) sfnt/ttcmap.c, (3) cff/cffgload.c, and (4) the read_lwfn function and a crafted LWFN file in base/ftmac.c. (CVE-2006-1861)

Ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference. (CVE-2006-2661)

In addition, a patch is applied to 2.1.10 in Mandriva 2006 to fix a serious bug in ttkern.c that caused some programs to go into an infinite loop when dealing with fonts that don't have a properly sorted kerning sub-table. This patch is not applicable to the earlier Mandriva releases.

Update :

The previous update introduced some issues with other applications and libraries linked to libfreetype, that were missed in testing for the vulnerability issues. The new packages correct these issues.

Solution

Update the affected packages.

Plugin Details

Severity: High

ID: 21715

File Name: mandrake_MDKSA-2006-099.nasl

Version: 1.21

Type: local

Published: 6/16/2006

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:lib64freetype6, p-cpe:/a:mandriva:linux:libfreetype6-static-devel, p-cpe:/a:mandriva:linux:lib64freetype6-devel, cpe:/o:mandriva:linux:2006, p-cpe:/a:mandriva:linux:lib64freetype6-static-devel, p-cpe:/a:mandriva:linux:libfreetype6, x-cpe:/o:mandrakesoft:mandrake_linux:le2005, p-cpe:/a:mandriva:linux:libfreetype6-devel

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/13/2006

Reference Information

CVE: CVE-2006-0747, CVE-2006-1861, CVE-2006-2661

BID: 18034, 18326, 18329

MDKSA: 2006:099-1