Bug 750942 (CVE-2012-1128) - VUL-0: CVE-2012-1128: freetype: NULL pointer dereference by moving zone2 pointer point for certain TrueType font
Summary: VUL-0: CVE-2012-1128: freetype: NULL pointer dereference by moving zone2 poin...
Status: RESOLVED FIXED
Alias: CVE-2012-1128
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: All Linux
: P3 - Medium : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:running:45961:important maint:r...
Keywords:
Depends on:
Blocks:
 
Reported: 2012-03-07 10:47 UTC by Ludwig Nussel
Modified: 2017-07-03 07:35 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Ludwig Nussel 2012-03-07 10:47:16 UTC
Your friendly security team received the following report via oss-sec.
Please respond ASAP.
The issue is public

CVE-2012-1128:
freetype: NULL pointer dereference by moving zone2 pointer point for certain TrueType font (FU#35601)

Upstream bug report:
[1] https://savannah.nongnu.org/bugs/?35601

Upstream patch:
[2] http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=96cddb8d1d32d6738b06552083db9d6cee5b5cb4


Red Hat Bugzilla entry:
[3] https://bugzilla.redhat.com/show_bug.cgi?id=800584
Comment 1 Swamp Workflow Management 2012-03-07 23:00:31 UTC
bugbot adjusting priority
Comment 2 Juergen Weigert 2012-03-28 13:41:41 UTC
sr#18319: osc submitpac SUSE:SLE-10-SP4:Update:Test
sr#18320: osc submitpac SUSE:SLE-11-SP1:GA
sr#18321: osc submitpac SUSE:SLE-11:Update:Test (superseeding 18320)
sr#18324: osc submitpac SUSE:SLE-9-SP3:Update:Teradata:Test
sr#18323: osc submitpac SUSE:SLE-9-SP4:GA
sr#111570: osc mr home:jnweiger:branches:OBS_Maintained:freetype2.openSUSE_11.4 freetype2 openSUSE:11.4
sr#111571: osc mr home:jnweiger:branches:OBS_Maintained:freetype2.openSUSE_12.1 freetype2 openSUSE:12.1
sr#111564: osc submitpac openSUSE:Factory

done.
Comment 3 Swamp Workflow Management 2012-04-11 15:53:21 UTC
Update released for: freetype2, freetype2-32bit, freetype2-debuginfo, freetype2-debuginfo-32bit, freetype2-debuginfo-64bit, freetype2-debuginfo-x86, freetype2-debugsource, freetype2-devel, freetype2-devel-32bit, freetype2-x86, ft2demos, ft2demos-debuginfo, ft2demos-debugsource
Products:
SLE-DEBUGINFO 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLE-DESKTOP 11-SP1 (i386, x86_64)
SLE-DESKTOP 11-SP1-FOR-SP2 (i386, x86_64)
SLE-SDK 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLE-SDK 11-SP1-FOR-SP2 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP1-FOR-SP2 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP1-TERADATA (x86_64)
SLES4VMWARE 11-SP1 (i386, x86_64)
Comment 4 Sebastian Krahmer 2012-04-23 10:01:11 UTC
done