Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Debian Local Security Checks >> [DSA1095] DSA-1095-1 freetype


Vulnerability Assessment Details

[DSA1095] DSA-1095-1 freetype

Vulnerability Assessment Summary
DSA-1095-1 freetype

Detailed Explanation for this Vulnerability Assessment

Several problems have been discovered in the FreeType 2 font engine.
The Common vulnerabilities and Exposures project identifies the
following problems:
Several integer underflows have been discovered which could permit
remote attackers to cause a denial of service.
Chris Evans discovered several integer overflows that lead to a
denial of service or could possibly even lead to the execution of
arbitrary code.
Several more integer overflows have been discovered which could
possibly lead to the execution of arbitrary code.
A null pointer dereference could cause a denial of service.
For the old stable distribution (woody) these problems have been fixed in
version 2.0.9-1woody1.
For the stable distribution (sarge) these problems have been fixed in
version 2.1.7-2.5.
For the unstable distribution (sid) these problems will be fixed soon
We recommend that you upgrade your libfreetype packages.


Solution : http://www.debian.org/security/2006/dsa-1095
Network Security Threat Level: High

Networks Security ID: 18034

Vulnerability Assessment Copyright: This script is (C) 2006 Michel Arboi

Cables, Connectors

NIB - Crucial Rendition 512MB PC2-4200 DDR2-533 240PIN DIMM Memory - 17799
$0.73
NIB - Crucial Rendition 512MB PC2-4200 DDR2-533 240PIN DIMM Memory - 17799 pictureKingston 4GB 1333MHz PC3-10600 DDR3 Laptop Memory KVR13S9S8/4
$15.0
Kingston  4GB 1333MHz PC3-10600 DDR3 Laptop Memory KVR13S9S8/4 pictureSamsung 16GB 2RX4 PC3L-10600R DDR3 1333mhz Only ECC Server Reg Memory RAM
$78.9
Samsung 16GB 2RX4 PC3L-10600R DDR3 1333mhz Only ECC Server Reg Memory RAM picturePNY 4GB 2x2 GB DDR2 800MHZ 667MHz 533MHz 400MHz
$48.0
PNY 4GB 2x2 GB DDR2 800MHZ  667MHz 533MHz 400MHz picture


Discussions

No Discussions have been posted on this vulnerability.