Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Debian Local Security Checks >> [DSA1095] DSA-1095-1 freetype


Vulnerability Assessment Details

[DSA1095] DSA-1095-1 freetype

Vulnerability Assessment Summary
DSA-1095-1 freetype

Detailed Explanation for this Vulnerability Assessment

Several problems have been discovered in the FreeType 2 font engine.
The Common vulnerabilities and Exposures project identifies the
following problems:
Several integer underflows have been discovered which could permit
remote attackers to cause a denial of service.
Chris Evans discovered several integer overflows that lead to a
denial of service or could possibly even lead to the execution of
arbitrary code.
Several more integer overflows have been discovered which could
possibly lead to the execution of arbitrary code.
A null pointer dereference could cause a denial of service.
For the old stable distribution (woody) these problems have been fixed in
version 2.0.9-1woody1.
For the stable distribution (sarge) these problems have been fixed in
version 2.1.7-2.5.
For the unstable distribution (sid) these problems will be fixed soon
We recommend that you upgrade your libfreetype packages.


Solution : http://www.debian.org/security/2006/dsa-1095
Network Security Threat Level: High

Networks Security ID: 18034

Vulnerability Assessment Copyright: This script is (C) 2006 Michel Arboi

Cables, Connectors

Polycom VVX 310 VoIP Business Media Phone 2201-46161-025 ***DOES NOT WORK***
$0.99
Polycom VVX 310 VoIP Business Media Phone 2201-46161-025 ***DOES NOT WORK*** pictureTRENDnet TVP-SP2 VoIP USB Speakerphone (for Skype)New in Shrink Nice Price$$
$4.98
TRENDnet TVP-SP2 VoIP USB Speakerphone (for Skype)New in Shrink Nice Price$$ pictureGRANDSTREAM GXV3240: 6 Line Multimedia IP Phone for Android *VoIP*
$100.0
GRANDSTREAM GXV3240: 6 Line Multimedia IP Phone for Android *VoIP* pictureCisco SPA504G 4-Line IP VoIP Telephone Phone PoE New
$20.0
Cisco SPA504G 4-Line IP VoIP Telephone Phone PoE New picture


Discussions

No Discussions have been posted on this vulnerability.