Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1148898
| Path | csiph.com!fu-berlin.de!bofh.it!news.nic.it!robomod |
|---|---|
| From | Salvatore Bonaccorso <carnil@debian.org> |
| Newsgroups | linux.debian.bugs.dist |
| Subject | Bug#1034612: freetype: CVE-2023-2004 |
| Date | Tue, 06 Jun 2023 22:40:01 +0200 |
| Message-ID | <GDLDb-e7W5-1@gated-at.bofh.it> (permalink) |
| References | <GmlF7-38BV-3@gated-at.bofh.it> <GmlF7-38BV-3@gated-at.bofh.it> |
| X-Original-To | 1034612@bugs.debian.org |
| X-Mailbox-Line | From debian-bugs-dist-request@lists.debian.org Tue Jun 6 20:39:09 2023 |
| Old-Return-Path | <debbugs@buxtehude.debian.org> |
| X-Spam-Flag | NO |
| X-Spam-Score | -4.01 |
| Reply-To | Salvatore Bonaccorso <carnil@debian.org>, 1034612@bugs.debian.org |
| Original-Sender | Salvatore Bonaccorso <salvatore.bonaccorso@gmail.com> |
| Resent-To | debian-bugs-dist@lists.debian.org |
| Resent-Cc | Hugh McMaster <hugh.mcmaster@outlook.com> |
| X-Debian-Pr-Message | followup 1034612 |
| X-Debian-Pr-Package | src:freetype |
| X-Debian-Pr-Keywords | security upstream |
| X-Debian-Pr-Source | freetype |
| X-Gm-Message-State | AC+VfDxSGVGQ8FyFvcb+VffAVz9rU7T979nbCWdqjIFRqfNWS/4igS6Z gi228DIeHKxCjlXCfij4xYBPZxkEz4KzRA== |
| X-Google-SMTP-Source | ACHHUZ6kwz4/LMgcDr39N6WO8+fXbZRFqHMYdPY+y4TVeFrT0XAC5w18npfRNOllC1tpp+pLhGE1nw== |
| X-Received | by 2002:a17:907:2d28:b0:973:e4c2:2bcd with SMTP id gs40-20020a1709072d2800b00973e4c22bcdmr3663403ejc.18.1686083692349; Tue, 06 Jun 2023 13:34:52 -0700 (PDT) |
| Sender | robomod@news.nic.it |
| Resent-To | 1034612@bugs.debian.org |
| MIME-Version | 1.0 |
| Content-Type | text/plain; charset=us-ascii |
| Content-Disposition | inline |
| X-Debian-Message | from BTS |
| X-Mailing-List | <debian-bugs-dist@lists.debian.org> archive/latest/1773974 |
| List-ID | <debian-bugs-dist.lists.debian.org> |
| List-URL | <https://lists.debian.org/debian-bugs-dist/> |
| Approved | robomod@news.nic.it |
| Lines | 23 |
| Organization | linux.* mail to news gateway |
| X-Original-Date | Tue, 6 Jun 2023 22:18:43 +0200 |
| X-Original-Message-ID | <ZH+Uo/l9du53zRro@eldamar.lan> |
| X-Original-References | <168193204862.1381673.2778663269639335520.reportbug@eldamar.lan> <168193204862.1381673.2778663269639335520.reportbug@eldamar.lan> |
| X-Original-Sender | Salvatore Bonaccorso <salvatore.bonaccorso@gmail.com> |
| Xref | csiph.com linux.debian.bugs.dist:1148898 |
Show key headers only | View raw
Control: retitle -1 src/truetype/ttgxvar.c (tt_hvadvance_adjust): Integer overflow. Control: tags -1 - security On Wed, Apr 19, 2023 at 09:20:48PM +0200, Salvatore Bonaccorso wrote: > Source: freetype > Version: 2.12.1+dfsg-4 > Severity: important > Tags: security upstream > X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org> > > Hi, > > The following vulnerability was published for freetype. > > CVE-2023-2004[0]: > | An integer overflow vulnerability was discovered in Freetype in > | tt_hvadvance_adjust() function in src/truetype/ttgxvar.c. The CVE got rejected by the assigning CNA as further investigation showed that there is no security issue. Regards, Salvatore
Back to linux.debian.bugs.dist | Previous | Next — Previous in thread | Find similar | Unroll thread
Bug#1034612: freetype: CVE-2023-2004 Salvatore Bonaccorso <carnil@debian.org> - 2023-04-19 21:30 +0200 Bug#1034612: freetype: CVE-2023-2004 Salvatore Bonaccorso <carnil@debian.org> - 2023-06-06 22:40 +0200
csiph-web