[ubuntu/xenial-security] fontforge 20120731.b-7.1ubuntu0.1 (Accepted)

Mike Salvatore mike.salvatore at canonical.com
Thu Dec 20 21:48:54 UTC 2018

fontforge (20120731.b-7.1ubuntu0.1) xenial-security; urgency=medium

  * SECURITY UPDATE: heap-based buffer over-read
    - debian/patches/CVE-2017-11568.patch: fix out
      of bounds read condition and buffer overflow in
      fontforge/parsettf.c, fontforge/psread.c,
    - CVE-2017-11568
  * SECURITY UPDATE: heap-based buffer over-read in
    - debian/patches/CVE-2017-11569-and-2017-11575.patch: fix
      out of bounds read condition in fontforge/parsettf.c.
    - CVE-2017-11569
    - CVE-2017-11575
  * SECURITY UPDATE: stack-based buffer overflow
    - debian/patches/CVE-2017-11571.patch: fix buffer overflow
      in fontforge/parsettf.c.
    - CVE-2017-11571
  * SECURITY UPDATE: stack underflow condition in
    - debian/patches/CVE-2017-11572-and-2017-11576.patch: prevent
      stack uderflow condition in fontforge/parsettf.c.
    - CVE-2017-11572
    - CVE-2017-11576
  * SECURITY UPDATE: heap-based buffer overflow in readcffset
    - debian/patches/CVE-2017-11574.patch: fix buffer condition
      in fontforge/parsetff.c.
    - CVE-2017-11574
  * SECURITY UPDATE: buffer over-read in getsid
    - debian/patches/CVE-2017-11577.patch: fix out of bounds read
      in fontforge/parsettf.c
    - CVE-2017-11577

Date: 2018-12-20 20:38:12.144731+00:00
Changed-By: Mike Salvatore <mike.salvatore at canonical.com>
-------------- next part --------------
Sorry, changesfile not available.

More information about the Xenial-changes mailing list