[rock-user] [Security Announcement] freetype (RLSA-20060627-01)

Daniel Jahre <[email protected]> Tue, 27 Jun 2006 15:04:51 +0200
Newsgroups gmane.linux.distributions.rock.user
Organization ROCK Linux
Message-ID <[email protected]>
This is a ROCK Linux Security Announcement.

Package: freetype
Announcement ID: RLSA-20060627-01
Date: 2006-06-27
Affected Distributions:  Crystal, LiveCD
Affected Releases: Crystal ROCK CLT
Cross References: CVE-2006-0747, CVE-2006-1861, CVE-2006-2661
Fixed at trunk revision: 7689

Content of this advisory:
1) Problem Description
2) Solution or Work-Around
3) Special instructions and notes
4) Updateing your source tree
5) Source package update
6) Binary package update

--------------------------------------------------------------------------------

1) Problem Description

freetype2 is used by a lot of applications. In versions prior 2.2.1 integer 
overflows are found that may lead to remote denial of service attacks and 
remote command execution.

2) Solution or Workaround
There is no known Work-Around. Please update the package.

3) Special instruction and notes
This update is binary compatible with freetype 2.1.7 so it should fit into 
most installed systems.

4) Updateing your source tree
If you are using a subversion checkout of trunk, run:
 svn up

If you are using submaster run,
 sm sync
to merge the update from trunk into your tree

5) Source package update
As a user of an affected distribution you can update this package by
rebuilding it on your machine
run
 rocket updsrc
to update your local sources and
 rocket emerge freetype
to install the updated package

6) Binary package update
there are no new binary packages available for this package yet.