[El-errata] ELSA-2013-0216 Important: Oracle Linux 6 freetype security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Fri Feb 1 04:48:32 PST 2013


Oracle Linux Security Advisory ELSA-2013-0216

https://rhn.redhat.com/errata/RHSA-2013-0216.html

The following updated rpms for Oracle Linux 6 have been uploaded to the 
Unbreakable Linux Network:

i386:
freetype-2.3.11-14.el6_3.1.i686.rpm
freetype-demos-2.3.11-14.el6_3.1.i686.rpm
freetype-devel-2.3.11-14.el6_3.1.i686.rpm

x86_64:
freetype-2.3.11-14.el6_3.1.i686.rpm
freetype-2.3.11-14.el6_3.1.x86_64.rpm
freetype-demos-2.3.11-14.el6_3.1.x86_64.rpm
freetype-devel-2.3.11-14.el6_3.1.i686.rpm
freetype-devel-2.3.11-14.el6_3.1.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol6/SRPMS-updates/freetype-2.3.11-14.el6_3.1.src.rpm



Description of changes:

[2.3.11-14.el6_3.1]
- Fix CVE-2012-5669
     (Use correct array size for checking `glyph_enc')
- Resolves: #903542

[2.3.11-14]
- A little change in configure part
- Related: #723468

[2.3.11-13]
- Fix CVE-2012-{1126, 1127, 1130, 1131, 1132, 1134, 1136,
   1137, 1139, 1140, 1141, 1142, 1143, 1144}
- Properly initialize array "result" in
   FT_Outline_Get_Orientation()
- Check bytes per row for overflow in _bdf_parse_glyphs()
- Resolves: #806269

[2.3.11-12]
- Add freetype-2.3.11-CVE-2011-3439.patch
     (Various loading fixes.)
- Resolves: #754012

[2.3.11-11]
- Add freetype-2.3.11-CVE-2011-3256.patch
     (Handle some border cases.)
- Resolves: #747084

[2.3.11-10]
- Use -fno-strict-aliasing instead of __attribute__((__may_alias__))
- Resolves: #723468

[2.3.11-9]
- Allow FT_Glyph to alias (to pass Rpmdiff)
- Resolves: #723468

[2.3.11-8]
- Add freetype-2.3.11-CVE-2011-0226.patch
     (Add better argument check for `callothersubr'.)
     - based on patches by Werner Lemberg,
       Alexei Podtelezhnikov and Matthias Drochner
- Resolves: #723468

[2.3.11-7]
- Add freetype-2.3.11-CVE-2010-3855.patch
     (Protect against invalid `runcnt' values.)
- Resolves: #651762





More information about the El-errata mailing list