U radu programskog paketa t1lib uočeno je više sigurnosnih propusta. Udaljeni ih napadač može iskoristiti da DoS (eng. Denial of Service) napad, otkrivanje osjetljivih podataka te proizvoljno pokretanje programskog koda.
t1lib 5.x
Operacijski sustavi:
Debian Linux 5.0 (lenny), Debian Linux 6.0 (squeeze)
Sigurnosni propusti su posljedica višestrukih preljeva međuspremnika u "lib/t1lib/parseAFM.c", pogrešnog rukovanja pokazivačima na memorijske lokacije te tzv. "use-after-free" ranjivosti.
Udaljeni napadač navedene propuste može iskoristiti za proizvoljno izvršavanje programskog koda, napad uskraćivanjem usluga (DoS) te otkrivanje osjetljivih informacija podmetanjem posebno oblikovanih Type 1 fontova.
Svim se korisnicima navedenog programskog paketa, u svrhu zaštite sigurnosti, savjetuje njegova nadogradnja na novije inačice.
Hash: SHA1
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2388-1 Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://www.debian.org/security/ Yves-Alexis Perez
January 14, 2012 http://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : t1lib
Vulnerability : several
Problem type : local
Debian-specific: no
CVE ID : CVE-2010-2642 CVE-2011-0433 CVE-2011-0764 CVE-2011-1552
CVE-2011-1553 CVE-2011-1554
Debian Bug : 652996
Several vulnerabilities were discovered in t1lib, a Postscript Type 1
font rasterizer library, some of which might lead to code execution
through the opening of files embedding bad fonts.
A heap-based buffer overflow in the AFM font metrics parser
potentially leads to the execution of arbitrary code.
Another heap-based buffer overflow in the AFM font metrics
parser potentially leads to the execution of arbitrary code.
An invalid pointer dereference allows execution of arbitrary
code using crafted Type 1 fonts.
Another invalid pointer dereference results in an application
crash, triggered by crafted Type 1 fonts.
A use-after-free vulnerability results in an application
crash, triggered by crafted Type 1 fonts.
An off-by-one error results in an invalid memory read and
application crash, triggered by crafted Type 1 fonts.
For the oldstable distribution (lenny), this problem has been fixed in
version 5.1.2-3+lenny1.
For the stable distribution (squeeze), this problem has been fixed in
version 5.1.2-3+squeeze1.
For the testing distribution (wheezy), this problem has been fixed in
version 5.1.2-3.3.
For the unstable distribution (sid), this problem has been fixed in
version 5.1.2-3.3.
We recommend that you upgrade your t1lib packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
Version: GnuPG v1.4.9 (GNU/Linux)
To UNSUBSCRIBE, email to Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
with a subject of "unsubscribe". Trouble? Contact Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
Archive: http://lists.debian.org/Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
Posljednje sigurnosne preporuke