Scientific Linux Security Update : freetype on SL3.x, SL4.x, SL5.x i386/x86_64

This script is Copyright (C) 2012 Tenable Network Security, Inc.

Synopsis :

The remote Scientific Linux host is missing one or more security

Description :

Multiple flaws were discovered in FreeType's Printer Font Binary (PFB)
and TrueType Font (TTF) font-file format parsers. If a user loaded a
carefully crafted font-file with a program linked against FreeType, it
could cause the application to crash, or possibly execute arbitrary
code. (CVE-2008-1806, CVE-2008-1807, CVE-2008-1808)

Note: the flaw in FreeType's TrueType Font (TTF) font-file format
parser, covered by CVE-2008-1808, did not affect the freetype packages
as shipped in Scientific Linux 3, 4, and 5, as they are not compiled
with TTF Byte Code Interpreter (BCI) support.

See also :

Solution :

Update the affected packages.

Risk factor :

High / CVSS Base Score : 7.5

Family: Scientific Linux Local Security Checks

Nessus Plugin ID: 60427 ()

Bugtraq ID:

CVE ID: CVE-2008-1806