Re: [oss-security] CVE-2025-27363: out of bounds write in FreeType <= 2.13.0
mpsuzuki <[email protected]> Fri, 14 Mar 2025 10:19:07 +0900
| Newsgroups | gmane.comp.fonts.freetype.devel |
|---|---|
| Message-ID | <[email protected]> |
👍 On 2025/03/14 3:03, Alan Coopersmith wrote: > On 3/13/25 09:13, Hin-Tak Leung wrote: >> While I generally agree with the "upgrade if you worry about this" advice, I am >> also aware that the concern did not come from consumer desktops, but from >> embedded , mobile and shipped / long-term-maintained systems like Solaris, >> Android, Raspberry pi OS, etc. > > I can't speak to the others, but for Solaris, we upgraded FreeType from 2.13.0 > to 2.13.3 in our Solaris 11.4.75 support update which shipped in November. > > https://blogs.oracle.com/solaris/post/announcing-oracle-solaris-114-sru75 >