Bugzilla – Bug 1198832
VUL-0: CVE-2022-27405: freetype2,freetype: FreeType: Segmentation Fault
Last modified: 2024-06-10 12:19:09 UTC
rh#2077991 FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request. http://freetype.com https://gitlab.freedesktop.org/freetype/freetype/-/issues/1139 References: https://bugzilla.redhat.com/show_bug.cgi?id=2077991 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-27405 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27405 http://www.cvedetails.com/cve/CVE-2022-27405/ https://gitlab.freedesktop.org/freetype/freetype/-/issues/1139 http://freetype.com
Affected: - SUSE:SLE-15:Update/freetype2 2.10.1 Not Affected: - SUSE:SLE-11:Update/freetype 1.3.1 - SUSE:SLE-12:Update/freetype 1.3.1 - openSUSE:Backports:SLE-15-SP3/freetype 1.3.1 - openSUSE:Backports:SLE-15-SP4/freetype 1.3.1 - openSUSE:Factory/freetype 1.3.1 - SUSE:SLE-11:Update/freetype2 2.3.7 - SUSE:SLE-12-SP2:Update/freetype2 2.6.3 Already fixed: - openSUSE:Factory/freetype2 2.12.0
Any updates here?
SUSE-SU-2022:3252-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 1198823,1198830,1198832 CVE References: CVE-2022-27404,CVE-2022-27405,CVE-2022-27406 JIRA References: Sources used: openSUSE Leap Micro 5.2 (src): freetype2-2.10.4-150000.4.12.1 openSUSE Leap 15.4 (src): freetype2-2.10.4-150000.4.12.1, ft2demos-2.10.4-150000.4.12.1 openSUSE Leap 15.3 (src): freetype2-2.10.4-150000.4.12.1, ft2demos-2.10.4-150000.4.12.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP4 (src): ft2demos-2.10.4-150000.4.12.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (src): ft2demos-2.10.4-150000.4.12.1 SUSE Linux Enterprise Module for Basesystem 15-SP4 (src): freetype2-2.10.4-150000.4.12.1 SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): freetype2-2.10.4-150000.4.12.1 SUSE Linux Enterprise Micro 5.2 (src): freetype2-2.10.4-150000.4.12.1 SUSE Linux Enterprise Micro 5.1 (src): freetype2-2.10.4-150000.4.12.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:3252-2: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 1198823,1198830,1198832 CVE References: CVE-2022-27404,CVE-2022-27405,CVE-2022-27406 JIRA References: Sources used: SUSE Manager Server 4.1 (src): freetype2-2.10.4-150000.4.12.1, ft2demos-2.10.4-150000.4.12.1 SUSE Manager Retail Branch Server 4.1 (src): freetype2-2.10.4-150000.4.12.1, ft2demos-2.10.4-150000.4.12.1 SUSE Manager Proxy 4.1 (src): freetype2-2.10.4-150000.4.12.1, ft2demos-2.10.4-150000.4.12.1 SUSE Linux Enterprise Server for SAP 15-SP2 (src): freetype2-2.10.4-150000.4.12.1, ft2demos-2.10.4-150000.4.12.1 SUSE Linux Enterprise Server for SAP 15-SP1 (src): freetype2-2.10.4-150000.4.12.1 SUSE Linux Enterprise Server for SAP 15 (src): freetype2-2.10.4-150000.4.12.1 SUSE Linux Enterprise Server 15-SP2-LTSS (src): freetype2-2.10.4-150000.4.12.1, ft2demos-2.10.4-150000.4.12.1 SUSE Linux Enterprise Server 15-SP2-BCL (src): freetype2-2.10.4-150000.4.12.1, ft2demos-2.10.4-150000.4.12.1 SUSE Linux Enterprise Server 15-SP1-LTSS (src): freetype2-2.10.4-150000.4.12.1 SUSE Linux Enterprise Server 15-SP1-BCL (src): freetype2-2.10.4-150000.4.12.1 SUSE Linux Enterprise Server 15-LTSS (src): freetype2-2.10.4-150000.4.12.1 SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src): freetype2-2.10.4-150000.4.12.1, ft2demos-2.10.4-150000.4.12.1 SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src): freetype2-2.10.4-150000.4.12.1, ft2demos-2.10.4-150000.4.12.1 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): freetype2-2.10.4-150000.4.12.1 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src): freetype2-2.10.4-150000.4.12.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): freetype2-2.10.4-150000.4.12.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): freetype2-2.10.4-150000.4.12.1 SUSE Enterprise Storage 7 (src): freetype2-2.10.4-150000.4.12.1, ft2demos-2.10.4-150000.4.12.1 SUSE Enterprise Storage 6 (src): freetype2-2.10.4-150000.4.12.1 SUSE CaaS Platform 4.0 (src): freetype2-2.10.4-150000.4.12.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
fixed, please close.
All done, closing.