lp:ubuntu/dapper-updates/libxfont

Created by James Westby and last modified
Get this branch:
bzr branch lp:ubuntu/dapper-updates/libxfont
Members of Ubuntu branches can upload to this branch. Log in for directions.

Branch merges

Related bugs

Related blueprints

Branch information

Owner:
Ubuntu branches
Review team:
Ubuntu Development Team
Status:
Development

Recent revisions

8. By Kees Cook

* SECURITY UPDATE: overflow in PCF font handling.
* src/bitmap/pcfread.c: patched inline from upstream commit
  (b76df66d2c507898472bba0f9986ef5700029a36) CVE-2008-0006

7. By Kees Cook

* SECURITY UPDATE: root privilege escalation with BDF font overflows.
* src/bitmap/bdfread.c, src/fontfile/fontdir.c: upstream fixes to stop
  integer overflows.
* References
  CVE-2007-1351 CVE-2007-1352

6. By Martin Pitt

* SECURITY UPDATE: Root privilege escalation with crafted Type1 CID fonts.
* lib/font/Type1/afm.c: Fix integer overflow in CIDAFM(). [CVE-2006-3739]
* lib/font/Type1/scanfont.c: Fix integer overflow in scan_cidfont().
  [CVE-2006-3740]

5. By Martin Pitt

* SECURITY UPDATE: DoS (X server crash) and possible root privilege escalation.
* src/bitmap/pcfread.c: Check for integer overflows when parsing PCF font
  files to prevent exploitable buffer overflow.
* Patch taken from upstream git:
  http://gitweb.freedesktop.org/?p=xorg/lib/libXfont.git;a=commit;h=8d171fe61e564d8ed8f75034d4191062cecf190b
* CVE-2006-3467

4. By Daniel Stone <email address hidden>

Change dependency on x-common to x11-common.

3. By Daniel Stone <email address hidden>

Add libfontenc-dev and libfreetype6-dev to libxfont-dev, per
Requires.private.

2. By Daniel Stone <email address hidden>

Fix the XFONT_FONTCACHE/FONTCACHE define in configure.ac (close:
Ubuntu#14319).

1. By Daniel Stone <email address hidden>

Import upstream version 0.99.0+cvs.20050909

Branch metadata

Branch format:
Branch format 7
Repository format:
Bazaar repository format 2a (needs bzr 1.16 or later)
Stacked on:
lp:ubuntu/karmic/libxfont
This branch contains Public information 
Everyone can see this information.

Subscribers