SUSE-SU-2016:1149-1

Source
https://www.suse.com/support/update/announcement/2016/suse-su-20161149-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2016:1149-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2016:1149-1
Related
Published
2016-04-25T15:38:39Z
Modified
2025-05-02T04:04:15.666930Z
Upstream
Summary
Security update for freetype2
Details

This update of the freetype2 library fixes two security issues:

  • An infinite loop in parse_encoding in t1load.c (CVE-2014-9745, bsc#945849)
  • Use of uninitialized memory in psparserloadfield, t42parsefontmatrix and t1parsefont_matrix (CVE-2014-9747, bsc#947966)
References

Affected packages

SUSE:Linux Enterprise Software Development Kit 11 SP4 / freetype2

Package

Name
freetype2
Purl
pkg:rpm/suse/freetype2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.7-25.41.4

Ecosystem specific

{
    "binaries": [
        {
            "freetype2-devel-32bit": "2.3.7-25.41.4",
            "freetype2-devel": "2.3.7-25.41.4"
        }
    ]
}

SUSE:Linux Enterprise Server 11 SP4 / freetype2

Package

Name
freetype2
Purl
pkg:rpm/suse/freetype2&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.7-25.41.4

Ecosystem specific

{
    "binaries": [
        {
            "freetype2": "2.3.7-25.41.4",
            "freetype2-32bit": "2.3.7-25.41.4",
            "freetype2-x86": "2.3.7-25.41.4",
            "ft2demos": "2.3.7-25.41.4"
        }
    ]
}

SUSE:Linux Enterprise Server 11 SP4 / ft2demos

Package

Name
ft2demos
Purl
pkg:rpm/suse/ft2demos&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.7-25.41.4

Ecosystem specific

{
    "binaries": [
        {
            "freetype2": "2.3.7-25.41.4",
            "freetype2-32bit": "2.3.7-25.41.4",
            "freetype2-x86": "2.3.7-25.41.4",
            "ft2demos": "2.3.7-25.41.4"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 11 SP4 / freetype2

Package

Name
freetype2
Purl
pkg:rpm/suse/freetype2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.7-25.41.4

Ecosystem specific

{
    "binaries": [
        {
            "freetype2": "2.3.7-25.41.4",
            "freetype2-32bit": "2.3.7-25.41.4",
            "freetype2-x86": "2.3.7-25.41.4",
            "ft2demos": "2.3.7-25.41.4"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 11 SP4 / ft2demos

Package

Name
ft2demos
Purl
pkg:rpm/suse/ft2demos&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.7-25.41.4

Ecosystem specific

{
    "binaries": [
        {
            "freetype2": "2.3.7-25.41.4",
            "freetype2-32bit": "2.3.7-25.41.4",
            "freetype2-x86": "2.3.7-25.41.4",
            "ft2demos": "2.3.7-25.41.4"
        }
    ]
}