[ubuntu/xenial-security] harfbuzz 1.0.1-1ubuntu0.1 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Wed Aug 24 13:15:04 UTC 2016


harfbuzz (1.0.1-1ubuntu0.1) xenial-security; urgency=medium

  * SECURITY UPDATE: memory access issue in hb-ot-layout-gpos-table.hh
    - debian/patches/CVE-2015-8947.patch: call check_struct earlier in
      src/hb-ot-layout-gpos-table.hh.
    - CVE-2015-8947
  * SECURITY UPDATE: buffer over-read via inverted length check
    - debian/patches/CVE-2016-2052.patch: fix hmtx wrong table length check
      in src/hb-ot-font.cc.
    - CVE-2016-2052

Date: 2016-08-17 15:46:18.041889+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/harfbuzz/1.0.1-1ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Xenial-changes mailing list