[ubuntu/trusty-updates] fontforge 20120731.b-5ubuntu0.1 (Accepted)

Ubuntu Archive Robot cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk
Mon Sep 4 16:28:07 UTC 2017


fontforge (20120731.b-5ubuntu0.1) trusty-security; urgency=medium

  * SECURITY UPDATE: heap-based buffer over-read
    - debian/patches/CVE-2017-11568.patch: fix out
      of bounds read condition and buffer overflow in
      fontforge/parsettf.c, fontforge/psread.c,
      fontforge/tottf.c.
    - CVE-2017-11568
  * SECURITY UPDATE: heap-based buffer over-read in
    readttfcopyrights
    - debian/patches/CVE-2017-11569-and-2017-11575.patch: fix
      out of bounds read condition in fontforge/parsettf.c.
    - CVE-2017-11569
    - CVE-2017-11575
  * SECURITY UPDATE: stack-based buffer overflow
    - debian/patches/CVE-2017-11571.patch: fix buffer overflow
      in fontforge/parsettf.c.
    - CVE-2017-11571
  * SECURITY UPDATE: stack underflow condition in
    readcfftopdicts
    - debian/patches/CVE-2017-11572-and-2017-11576.patch: prevent
      stack uderflow condition in fontforge/parsettf.c.
    - CVE-2017-11572
    - CVE-2017-11576
  * SECURITY UPDATE: heap-based buffer overflow in readcffset
    - debian/patches/CVE-2017-11574.patch: fix buffer condition
      in fontforge/parsetff.c.
    - CVE-2017-11574
  * SECURITY UPDATE: buffer over-read in getsid
    - debian/patches/CVE-2017-11577.patch: fix out of bounds read
      in fontforge/parsettf.c
    - CVE-2017-11577

Date: 2017-08-30 15:18:13.994430+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
Signed-By: Ubuntu Archive Robot <cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk>
https://launchpad.net/ubuntu/+source/fontforge/20120731.b-5ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Trusty-changes mailing list