freetype 2.10.1-2ubuntu0.2 source package in Ubuntu

Changelog

freetype (2.10.1-2ubuntu0.2) focal-security; urgency=medium

  * SECURITY UPDATE: Heap buffer overflow in sfnt_init_face
    - debian/patches/CVE-2022-27404.patch: avoid invalid face index in
      src/sfnt/sfobjs.c.
    - CVE-2022-27404
  * SECURITY UPDATE: Segmentation violation in FNT_Size_Request
    - debian/patches/CVE-2022-27405.patch: properly guard face_index in
      src/base/ftobjs.c.
    - CVE-2022-27405
  * SECURITY UPDATE: Segmentation violation in FT_Request_Size
    - debian/patches/CVE-2022-27406.patch: guard face->size in
      src/base/ftobjs.c.
    - CVE-2022-27406
  * SECURITY UPDATE: Heap-based buffer overflow in ftbench demo
    - debian/patches/CVE-2022-31782.patch: check the number of glyphs in
      ft2demos/src/ftbench.c.
    - CVE-2022-31782

 -- Marc Deslauriers <email address hidden>  Tue, 19 Jul 2022 11:28:34 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Focal
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
libs
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
freetype_2.10.1.orig-ft2demos.tar.gz 298.2 KiB 5e9e94a2db9d1a945293a1644a502f6664a2173a454d4a55b19695e2e2f4a0bc
freetype_2.10.1.orig-ft2demos.tar.gz.asc 195 bytes ccee51c4b4101b89a66ba5f2bdd54d127e93e120086982db57fa33761f310e9e
freetype_2.10.1.orig-ft2docs.tar.gz 2.0 MiB a4e4a8e69c7bf833eba7c158254a572fd43131d5e9b8791bd2ecbb03546ce155
freetype_2.10.1.orig-ft2docs.tar.gz.asc 195 bytes aaedd84036d9e615fbb5acf71081dd05c9d7333686593432e445ee89655a79c9
freetype_2.10.1.orig.tar.gz 3.3 MiB 3a60d391fd579440561bf0e7f31af2222bc610ad6ce4d9d7bd2165bca8669110
freetype_2.10.1.orig.tar.gz.asc 195 bytes 3952cc2651536ef5157601143d1efc453a7fe5ca64eaf765d034c417aabd4210
freetype_2.10.1-2ubuntu0.2.debian.tar.xz 113.9 KiB acea22b20f822dc79a24ee1704f23c6b9345ca4bf3fe4527fb54fefa90626451
freetype_2.10.1-2ubuntu0.2.dsc 3.8 KiB 8d8c33b0251ae7d2066b0d1a9cf197610876da1d16cf7f8f99b6bdf5c5d1c310

View changes file

Binary packages built by this source

freetype2-demos: FreeType 2 demonstration programs

 The FreeType project is a team of volunteers who develop free,
 portable and high-quality software solutions for digital typography.
 They specifically target embedded systems and focus on providing small,
 efficient and ubiquitous products.
 .
 This package contains some demonstration programs and utilities
 that showcase the features of the FreeType 2 font engine.

freetype2-demos-dbgsym: debug symbols for freetype2-demos
freetype2-doc: FreeType 2 font engine, development documentation

 The FreeType project is a team of volunteers who develop free,
 portable and high-quality software solutions for digital typography.
 They specifically target embedded systems and focus on providing small,
 efficient and ubiquitous products.
 .
 This package contains the FreeType 2 development documentation.

libfreetype-dev: FreeType 2 font engine, development files

 The FreeType project is a team of volunteers who develop free,
 portable and high-quality software solutions for digital typography.
 They specifically target embedded systems and focus on providing small,
 efficient and ubiquitous products.
 .
 This package contains all of the supplementary files you need to develop your
 own programs using the FreeType 2 library.

libfreetype6: FreeType 2 font engine, shared library files

 The FreeType project is a team of volunteers who develop free,
 portable and high-quality software solutions for digital typography.
 They specifically target embedded systems and focus on providing small,
 efficient and ubiquitous products.
 .
 The FreeType 2 library is their new software font engine. It has been
 designed to provide the following important features:
  * A universal and simple API to manage font files
  * Support for several font formats through loadable modules
  * High-quality anti-aliasing
  * High portability & performance
 .
 Supported font formats include:
  * TrueType files (.ttf) and collections (.ttc)
  * Type 1 font files both in ASCII (.pfa) or binary (.pfb) format
  * Type 1 Multiple Master fonts. The FreeType 2 API also provides
    routines to manage design instances easily
  * Type 1 CID-keyed fonts
  * OpenType/CFF (.otf) fonts
  * CFF/Type 2 fonts
  * Adobe CEF fonts (.cef), used to embed fonts in SVG documents with
    the Adobe SVG viewer plugin.
  * Windows FNT/FON bitmap fonts
 .
 This package contains the files needed to run programs that use the
 FreeType 2 library.

libfreetype6-dbgsym: debug symbols for libfreetype6
libfreetype6-dev: FreeType 2 font engine, development files (transitional package)

 The FreeType project is a team of volunteers who develop free,
 portable and high-quality software solutions for digital typography.
 They specifically target embedded systems and focus on providing small,
 efficient and ubiquitous products.
 .
 This package contains all of the supplementary files you need to develop your
 own programs using the FreeType 2 library.
 .
 This is a transitional package. It can safely be removed.

libfreetype6-udeb: FreeType 2 font engine for the debian-installer

 The FreeType project is a team of volunteers who develop free,
 portable and high-quality software solutions for digital typography.
 They specifically target embedded systems and focus on providing small,
 efficient and ubiquitous products.
 .
 This is the udeb package for use with the debian-installer.