From 2f6d7004e06dfb3d395547c81289abf44cb1b2ac Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Sat, 3 Feb 2024 08:57:49 +0000 Subject: [ GLSA 202402-06 ] FreeType: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/840224 Bug: https://bugs.gentoo.org/881443 Signed-off-by: GLSAMaker Signed-off-by: Hans de Graaff --- glsa-202402-06.xml | 46 ++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 46 insertions(+) create mode 100644 glsa-202402-06.xml (limited to 'glsa-202402-06.xml') diff --git a/glsa-202402-06.xml b/glsa-202402-06.xml new file mode 100644 index 00000000..b36fa0e6 --- /dev/null +++ b/glsa-202402-06.xml @@ -0,0 +1,46 @@ + + + + FreeType: Multiple Vulnerabilities + Multiple vulnerabilities have been discovered in FreeType, the worst of which can lead to remote code execution. + freetype + 2024-02-03 + 2024-02-03 + 840224 + 881443 + local and remote + + + 2.13.0 + 2.13.0 + + + +

FreeType is a high-quality and portable font engine.

+
+ +

Multiple vulnerabilities have been discovered in FreeType. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All FreeType users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=media-libs/freetype-2.13.0" + +
+ + CVE-2022-27404 + CVE-2022-27405 + CVE-2022-27406 + CVE-2023-2004 + + graaff + graaff +
\ No newline at end of file -- cgit v1.2.3-65-gdbad