MGASA-2017-0217

Source
https://advisories.mageia.org/MGASA-2017-0217.html
Import Source
https://advisories.mageia.org/MGASA-2017-0217.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2017-0217
Related
Published
2017-07-25T22:07:12Z
Modified
2017-07-25T08:14:12Z
Summary
Updated graphite2 packages fix security vulnerabilities
Details

An out-of-bounds write triggered with a maliciously crafted Graphite font could lead to a crash or potentially code execution (CVE-2017-5436).

Multiple vulnerabilities have been found in the Graphite font rendering engine which might result in denial of service or the execution of arbitrary code if a malformed font file is processed (CVE-2017-7771, CVE-2017-7772, CVE-2017-7773, CVE-2017-7774, CVE-2017-7775, CVE-2017-7776, CVE-2017-7777, CVE-2017-7778).

References
Credits

Affected packages

Mageia:5 / graphite2

Package

Name
graphite2
Purl
pkg:rpm/mageia/graphite2?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.10-1.mga5

Ecosystem specific

{
    "section": "core"
}