UbuntuUpdates.org

Package "libharfbuzz-dev"

Name: libharfbuzz-dev

Description:

Development files for OpenType text shaping engine

Latest version: 1.0.1-1ubuntu0.1
Release: xenial (16.04)
Level: updates
Repository: main
Head package: harfbuzz
Homepage: http://www.freedesktop.org/wiki/Software/HarfBuzz

Links


Download "libharfbuzz-dev"


Other versions of "libharfbuzz-dev" in Xenial

Repository Area Version
base main 1.0.1-1build2
security main 1.0.1-1ubuntu0.1

Changelog

Version: 1.0.1-1ubuntu0.1 2016-08-24 16:06:55 UTC

  harfbuzz (1.0.1-1ubuntu0.1) xenial-security; urgency=medium

  * SECURITY UPDATE: memory access issue in hb-ot-layout-gpos-table.hh
    - debian/patches/CVE-2015-8947.patch: call check_struct earlier in
      src/hb-ot-layout-gpos-table.hh.
    - CVE-2015-8947
  * SECURITY UPDATE: buffer over-read via inverted length check
    - debian/patches/CVE-2016-2052.patch: fix hmtx wrong table length check
      in src/hb-ot-font.cc.
    - CVE-2016-2052

 -- Marc Deslauriers <email address hidden> Wed, 17 Aug 2016 11:14:40 -0400

CVE-2015-8947 hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecif
CVE-2016-2052 Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of ser



About   -   Send Feedback to @ubuntu_updates