| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
| Name: libfreetype6-x86 | Distribution: openSUSE 11.4 |
| Version: 2.4.4 | Vendor: openSUSE |
| Release: 7.24.1 | Build date: Thu Mar 29 14:49:18 2012 |
| Group: System/Libraries | Build host: build19 |
| Size: 551144 | Source RPM: freetype2-2.4.4-7.24.1.src.rpm |
| Packager: http://bugs.opensuse.org | |
| Url: http://www.freetype.org | |
| Summary: A TrueType Font Library | |
This library features TrueType fonts for open source projects. This version also contains an autohinter for producing improved output.
Freetype License (BSD-like). See http://freetype.sourceforge.net/FTL.TXT
* Mon Mar 26 2012 jw@suse.com
- BNC#750937, BNC#750947 CVE-2012-1126+1127.patch Out-of heap-based buffer read by parsing glyph information and bitmaps for BDF fonts
- BNC#750938 CVE-2012-1139.patch Array index error, leading to out-of stack based buffer read by parsing BDF font glyph information
- BNC#750939 CVE-2012-1136.patch Out-of heap-based buffer write by parsing BDF glyph and bitmaps information with missing ENCODING field (FU#35641)
- BNC#750940 CVE-2012-1133.patch Out-of heap-based buffer write by parsing BDF glyph information and bitmaps (FU#35607)
- BNC#750941 CVE-2012-1138.patch Out-of heap-based buffer read in the TrueType bytecode interpreter by executing the MIRP instruction
- BNC#750942 CVE-2012-1128.patch NULL pointer dereference by moving zone2 pointer point for certain TrueType font
- BNC#750943 CVE-2012-1137.patch Out-of heap-based buffer read by parsing BDF font header
- BNC#750944 CVE-2012-1144.patch Out-of heap-based buffer write in the TrueType bytecode interpreter by moving zone2 pointer point
- BNC#750945 CVE-2012-1134.patch Out-of heap-based buffer write in Type1 font parser by retrieving font's private dictionary
- BNC#750946 CVE-2012-1135.patch Out-of heap-based buffer read in TrueType bytecode interpreter by executing NPUSHB and NPUSHW instructions (FU#35640)
- BNC#750947 CVE-2012-1127.patch Out-of heap-based buffer read by parsing glyph information and bitmaps for BDF fonts
- BNC#750948 CVE-2012-1142.patch Out-of heap-based buffer read in TrueType bytecode interpreter by executing NPUSHB and NPUSHW instructions
- BNC#750949 CVE-2012-1143.patch Integer divide by zero by performing arithmetic computations for certain fonts
- BNC#750950 CVE-2012-1132.patch Out-of heap-based buffer read flaw in Type1 font loader by parsing font dictionary entries
- BNC#750951 CVE-2012-1130.patch Out-of heap-based buffer read by loading properties of PCF fonts
- BNC#750952 CVE-2012-1129.patch Out-of heap-based buffer read when parsing certain SFNT strings by Type42 font parser
- BNC#750953 CVE-2012-1131.patch (64-bit specific): Out-of heap-based buffer read by attempt to record current cell into the cell table
- BNC#750954 CVE-2012-1140.patch Out-of heap-based buffer read by conversion of PostScript font objects
- BNC#750955 CVE-2012-1141.patch Out-of heap-based buffer read flaw by conversion of an ASCII string into a signed short integer by processing BDF fonts
* Fri Dec 16 2011 meissner@suse.de
(from evergreen)
- bnc730124_CVE-2011-3256.patch:
FreeType 2 before 2.4.7 allows remote attackers to execute arbitrary
code or cause a denial of service (memory corruption) via a crafted
font. (CVE-2011-3256, bnc#730124)
- bnc730124_CVE-2011-3439.patch:
FreeType allows remote attackers to execute arbitrary code or cause a
denial of service (memory corruption) via a crafted font.
(CVE-2011-3439, bnc#730124)
* Thu Jul 21 2011 mls@suse.de
- added bnc704612_othersubr.diff, CVE-2011-0226, bnc#704612
* Tue Dec 07 2010 jw@novell.com
- several old patches got lost, reapplying:
* added bnc641580_CVE-2010-3311.diff for bnc#641580
* bnc633943_CVE-2010-3054 nothing to do.
* bnc633938_CVE-2010-3053 nothing to do.
* Mon Dec 06 2010 cristian.rodriguez@opensuse.org
- exclude *.a *.la files from -devel package
* Sat Dec 04 2010 pascal.bleser@opensuse.org
- Updated to version 2.4.4:
* [truetype] better multi-threading support
* [truetype] identify the tricky fonts by cvt/fpgm/prep checksums; some Latin TrueType fonts are still expected to be unhinted
* [type1] fix matrix normalization
* [type1] improve guard against malformed data
* [ftsmooth] improve rendering
* [ftraster] fix rendering
* Fri Oct 29 2010 fisiu@opensuse.org
- Updated to version 2.4.3:
+ Fix rendering of certain cubic, S-shaped arcs. This regression
has been introduced in version 2.4.0.
+ Handling of broken fonts has been further improved.
* Thu Aug 12 2010 jw@novell.com
- bnc#628213: added bnc628213_1797.diff
- bnc#629447: CVE-2010-2805..8 are already fixed in upstream 2.4.2
- bnc#619562: CVE-2010-2497,2498,2499,2500,2519,2520 dito.
* Mon Aug 09 2010 tiwai@suse.de
- updated to version 2.4.2:
Another serious bug in the CFF font module has been found,
together with more exploitable vulnerabilities in the T42 font
driver.
* Tue Jul 20 2010 tiwai@suse.de
- updated to version 2.4.1:
* major version up
* bytecode interpreter is enabled as default in the upstream
* doc-reference is redundant, removed
* Fri Jun 04 2010 coolo@novell.com
- reenable bitmap foundaries (bnc#596559)
* Sat Apr 24 2010 coolo@novell.com
- buildrequire pkg-config to fix provides
* Tue Apr 06 2010 aj@suse.de
- Adjust baselibs.conf for changes
* Tue Apr 06 2010 coolo@novell.com
- fix obsoletes/provides
* Mon Apr 05 2010 coolo@novell.com
- leave freetype2 behind and only go with shared library package
* Sun Apr 04 2010 aj@suse.de
- Fix baselibs.conf for renamed libs
* Wed Mar 31 2010 coolo@novell.com
- update to version 2.3.12:
brings considerable improvements for b/w rasterizing of hinted
TrueType fonts at small sizes, see NEWS for more details
- fixed build without sysvinit in the build system
- disable no longer compiling patch that should be upstream or dead
- split out shared library policy package
- remove old patches
* Mon Dec 14 2009 jengelh@medozas.de
- add baselibs.conf as a source
* Fri Nov 06 2009 tiwai@suse.de
- make -std=gnu99 cfalgs to be ARM-specific
* Tue Nov 03 2009 coolo@novell.com
- updated patches to apply with fuzz=0
* Sun Aug 02 2009 jansimon.moeller@opensuse.org
- ARM build needs -std=gnu99 in CFLAGS
* Mon Jul 27 2009 tiwai@suse.de
- updated to version 2.3.8:
* see URLs below
http://www.freetype.org/index2.html#release-freetype-2.3.8
http://sourceforge.net/project/shownotes.php?group_id=3157&release_id=653641
- updated to version 2.3.9:
* see URLs below
http://www.freetype.org/index2.html#release-freetype-2.3.9
http://sourceforge.net/project/shownotes.php?group_id=3157&release_id=667610
- fix builds with older distros
* Tue Jul 07 2009 meissner@novell.com
- require zlib-devel-<targettype> from freetype2-devel-<targettype>
bnc#519192
* Thu Apr 16 2009 nadvornik@suse.cz
- fixed integer overflows [bnc#485889] CVE-2009-0946
* Mon Mar 09 2009 crrodriguez@suse.de
- freetype2 has subpixel rendering enabled [bnc#478407]
/emul/ia32-linux/usr /emul/ia32-linux/usr/lib /emul/ia32-linux/usr/lib/libfreetype.so.6 /emul/ia32-linux/usr/lib/libfreetype.so.6.6.2
Generated by rpm2html 1.8.1
Fabrice Bellet, Mon May 13 08:46:15 2013