UbuntuUpdates.org

Package "libxfont-dev"

Name: libxfont-dev

Description:

X11 font rasterisation library (development headers)

Latest version: 1:2.0.1-3~ubuntu16.04.3
Release: xenial (16.04)
Level: security
Repository: main
Head package: libxfont2

Links


Download "libxfont-dev"


Other versions of "libxfont-dev" in Xenial

Repository Area Version
base main 1:1.5.1-1
updates main 1:2.0.1-3~ubuntu16.04.3

Changelog

Version: 1:2.0.1-3~ubuntu16.04.3 2017-11-29 19:06:47 UTC

  libxfont2 (1:2.0.1-3~ubuntu16.04.3) xenial-security; urgency=medium

  * SECURITY UPDATE: non-privileged arbitrary file access
    - debian/patches/CVE-2017-16611.patch: open files with O_NOFOLLOW in
      src/fontfile/dirfile.c, src/fontfile/fileio.c.
    - CVE-2017-16611

 -- Marc Deslauriers <email address hidden> Tue, 28 Nov 2017 14:45:33 -0500

Source diff to previous version
CVE-2017-16611 Open files with O_NOFOLLOW

Version: 1:2.0.1-3~ubuntu16.04.2 2017-10-10 16:06:58 UTC

  libxfont2 (1:2.0.1-3~ubuntu16.04.2) xenial-security; urgency=medium

  * SECURITY UPDATE: invalid memory read in PatternMatch
    - debian/patches/CVE-2017-13720.patch: check for end of string in
      src/fontfile/fontdir.c.
    - CVE-2017-13720
  * SECURITY UPDATE: DoS or info leak via malformed PCF file
    - debian/patches/CVE-2017-13722.patch: check string boundaries in
      src/bitmap/pcfread.c.
    - CVE-2017-13722

 -- Marc Deslauriers <email address hidden> Fri, 06 Oct 2017 11:45:51 -0400

CVE-2017-1372 IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri



About   -   Send Feedback to @ubuntu_updates