Skip to content
  1. Feb 18, 2016
  2. Feb 17, 2016
  3. Feb 16, 2016
  4. Feb 15, 2016
    • Gustavo Zacarias's avatar
      graphite2: security bump to version 1.3.5 · 36bdaa2e
      Gustavo Zacarias authored
      
      
      Fixes:
      CVE-2016-1521 - An exploitable out-of-bounds read vulnerability exists
      in the opcode handling functionality of Libgraphite. A specially crafted
      font can cause an out-of-bounds read resulting in arbitrary code
      execution. An attacker can provide a malicious font to trigger this
      vulnerability.
      CVE-2016-1522 - An exploitable NULL pointer dereference exists in the
      bidirectional font handling functionality of Libgraphite. A specially
      crafted font can cause a NULL pointer dereference resulting in a crash.
      An attacker can provide a malicious font to trigger this vulnerability.
      CVE-2016-1523 - An exploitable heap-based buffer overflow exists in the
      context item handling functionality of Libgraphite. A specially crafted
      font can cause a buffer overflow resulting in potential code execution.
      An attacker can provide a malicious font to trigger this vulnerability.
      
      Signed-off-by: default avatarGustavo Zacarias <gustavo@zacarias.com.ar>
      Signed-off-by: default avatarThomas Petazzoni <thomas.petazzoni@free-electrons.com>
      36bdaa2e
  5. Feb 14, 2016
  6. Feb 13, 2016
Loading