Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Debian Local Security Checks >> [DSA1095] DSA-1095-1 freetype


Vulnerability Assessment Details

[DSA1095] DSA-1095-1 freetype

Vulnerability Assessment Summary
DSA-1095-1 freetype

Detailed Explanation for this Vulnerability Assessment

Several problems have been discovered in the FreeType 2 font engine.
The Common vulnerabilities and Exposures project identifies the
following problems:
Several integer underflows have been discovered which could permit
remote attackers to cause a denial of service.
Chris Evans discovered several integer overflows that lead to a
denial of service or could possibly even lead to the execution of
arbitrary code.
Several more integer overflows have been discovered which could
possibly lead to the execution of arbitrary code.
A null pointer dereference could cause a denial of service.
For the old stable distribution (woody) these problems have been fixed in
version 2.0.9-1woody1.
For the stable distribution (sarge) these problems have been fixed in
version 2.1.7-2.5.
For the unstable distribution (sid) these problems will be fixed soon
We recommend that you upgrade your libfreetype packages.


Solution : http://www.debian.org/security/2006/dsa-1095
Network Security Threat Level: High

Networks Security ID: 18034

Vulnerability Assessment Copyright: This script is (C) 2006 Michel Arboi

Cables, Connectors

EMC / Finisar FTLX8571D3BCL-E5 10GbE & 10GbFC SW EMC 019-078-041 SFP+
$16.95
EMC / Finisar FTLX8571D3BCL-E5 10GbE & 10GbFC SW EMC 019-078-041 SFP+ picture10051 Extreme Networks SFP SX GBIC 4050-00010 Genuine
$15.0
10051 Extreme Networks SFP SX GBIC 4050-00010 Genuine  pictureCisco WS-C3560G-24PS-S 24x Ethernet 10/100/1000 ports and 4x SFP Port Switch
$150.0
Cisco WS-C3560G-24PS-S 24x Ethernet 10/100/1000 ports and 4x SFP Port Switch  pictureCisco Original TRP-03BCS OC3 10-1308-01 1310nm Wavelength MMF SFP BA4APX0BAA GGS
$45.0
Cisco Original TRP-03BCS OC3 10-1308-01 1310nm Wavelength MMF SFP BA4APX0BAA GGS picture


Discussions

No Discussions have been posted on this vulnerability.