Bug 730124 - VUL-0: freetype2: buffer overflows
VUL-0: freetype2: buffer overflows
Status: RESOLVED FIXED
: 728044 (view as bug list)
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: General
unspecified
Other Other
: P2 - High : Major
: ---
Assigned To: Security Team bot
Security Team bot
maint:released:sle10-sp4:44369 maint:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2011-11-14 10:17 UTC by Matthias Weckbecker
Modified: 2012-04-23 12:53 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matthias Weckbecker 2011-11-14 10:17:27 UTC
There have been two issues in freetype reported recently,

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3256
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3439

Both will potentially allow the execution of arbitrary code.
Comment 1 Matthias Weckbecker 2011-11-14 10:28:41 UTC
Fix for CVE-2011-3256 is available at:

http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=9c98fbf634a83c6ea286395f0e788956eafd5aeb
Comment 2 Matthias Weckbecker 2011-11-14 10:33:18 UTC
Fix for CVE-2011-3439 is available at:

http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=14a16e3430ce85538ba9116816cf463cf8827708
Comment 3 Swamp Workflow Management 2011-11-14 10:34:09 UTC
The SWAMPID for this issue is 44139.
This issue was rated as important.
Please submit fixed packages until 2011-11-21.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 4 Matthias Weckbecker 2011-11-15 09:47:35 UTC
*** Bug 728044 has been marked as a duplicate of this bug. ***
Comment 5 Marcus Meissner 2011-11-28 13:42:38 UTC
hello juergen ... 

this is now 1 week over the hard deadline, please submit ASAP
Comment 6 Juergen Weigert 2011-11-28 23:07:59 UTC
ibs: created request id 16700 for SUSE_SLE-11-SP1_GA
ibs: created request id 16701 for SUSE_SLE-11_Update_Test
ibs: created request id 16702 for SUSE_SLE-10-SP4_Update_Test (also fixes bnc#711487)
ibs: created request id 16703 for SUSE_SLE-9-SP4_GA
Comment 8 Juergen Weigert 2011-12-01 15:37:40 UTC
check_if_valid_source_dir delays submissions, if not all existing patches are used. Commented them out.
submitted 16737 to supercede 16700
submitted 16738 to supercede 16701
submitted 16739 to supercede 16702
submitted 16740 to supercede 16703 (this time I was asked to actually supersede)
Comment 12 Swamp Workflow Management 2011-12-08 00:21:04 UTC
Update released for: freetype2, freetype2-32bit, freetype2-64bit, freetype2-debuginfo, freetype2-devel, freetype2-devel-32bit, freetype2-devel-64bit, freetype2-x86
Products:
SLE-DESKTOP 10-SP4 (i386, x86_64)
SLE-SERVER 10-SP4 (i386, ia64, ppc, s390x, x86_64)
Comment 13 Swamp Workflow Management 2011-12-08 01:08:26 UTC
Update released for: freetype2, freetype2-32bit, freetype2-debuginfo, freetype2-debuginfo-32bit, freetype2-debuginfo-64bit, freetype2-debuginfo-x86, freetype2-debugsource, freetype2-devel, freetype2-devel-32bit, freetype2-x86
Products:
SLE-DEBUGINFO 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLE-DESKTOP 11-SP1 (i386, x86_64)
SLE-SDK 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP1-TERADATA (x86_64)
SLES4VMWARE 11-SP1 (i386, x86_64)
Comment 14 Bernhard Wiedemann 2011-12-09 00:00:14 UTC
This is an autogenerated message for OBS integration:
This bug (730124) was mentioned in
https://build.opensuse.org/request/show/96030 Evergreen:11.1 / freetype2
https://build.opensuse.org/request/show/96031 Evergreen:11.2 / freetype2
Comment 15 Swamp Workflow Management 2011-12-09 10:35:31 UTC
Update released for: freetype2, freetype2-32bit, freetype2-debuginfo, freetype2-devel, freetype2-devel-32bit
Products:
SLE-SERVER 10-SP3-TERADATA (x86_64)
Comment 16 Bernhard Wiedemann 2011-12-09 21:00:11 UTC
This is an autogenerated message for OBS integration:
This bug (730124) was mentioned in
https://build.opensuse.org/request/show/96213 Evergreen:11.1 / freetype2
Comment 17 Swamp Workflow Management 2011-12-12 18:07:10 UTC
Update released for: freetype2, freetype2-devel
Products:
SUSE-CORE 9-SP3-TERADATA (x86_64)
Comment 18 Marcus Meissner 2011-12-16 14:32:50 UTC
CVE-2011-3439 was already fixed in the freetype2 in openSUSE 12.1 GA.
Comment 19 Marcus Meissner 2011-12-16 14:38:16 UTC
openSUSE 12.1 also not affected by other CVE (was fixed before shipment)
Comment 20 Marcus Meissner 2011-12-16 14:48:32 UTC
correction, CVE-2011-3439 was NOT fixed in the freetype2 in openSUSE 12.1 GA. will be in this update.
Comment 21 Marcus Meissner 2011-12-16 15:15:05 UTC
submitted 11.3, 11.4 and 12.1 based on the evergreen patches.
Comment 22 Bernhard Wiedemann 2011-12-16 16:00:09 UTC
This is an autogenerated message for OBS integration:
This bug (730124) was mentioned in
https://build.opensuse.org/request/show/96870 11.3 / freetype2
https://build.opensuse.org/request/show/96871 12.1 / freetype2
Comment 23 Bernhard Wiedemann 2011-12-19 10:00:09 UTC
This is an autogenerated message for OBS integration:
This bug (730124) was mentioned in
https://build.opensuse.org/request/show/96997 12.1 / freetype2
Comment 24 Ludwig Nussel 2011-12-21 09:14:17 UTC
released
Comment 25 Swamp Workflow Management 2011-12-29 16:12:51 UTC
Update released for: freetype2, freetype2-debugsource, freetype2-devel, libfreetype6, libfreetype6-debuginfo
Products:
openSUSE 11.3 (debug, i586, x86_64)
openSUSE 11.4 (debug, i586, x86_64)
Comment 26 Swamp Workflow Management 2012-04-23 12:53:05 UTC
Update released for: freetype2, freetype2-32bit, freetype2-debuginfo, freetype2-devel, freetype2-devel-32bit, ft2demos, ft2demos-debuginfo
Products:
SLE-SERVER 10-SP2-LTSS (i386, s390x, x86_64)