Scientific Linux Security Update : freetype on SL3.x, SL4.x, SL5.x i386/x86_64
High Nessus Plugin ID 60427
SynopsisThe remote Scientific Linux host is missing one or more security updates.
DescriptionMultiple flaws were discovered in FreeType's Printer Font Binary (PFB) and TrueType Font (TTF) font-file format parsers. If a user loaded a carefully crafted font-file with a program linked against FreeType, it could cause the application to crash, or possibly execute arbitrary code. (CVE-2008-1806, CVE-2008-1807, CVE-2008-1808)
Note: the flaw in FreeType's TrueType Font (TTF) font-file format parser, covered by CVE-2008-1808, did not affect the freetype packages as shipped in Scientific Linux 3, 4, and 5, as they are not compiled with TTF Byte Code Interpreter (BCI) support.
SolutionUpdate the affected packages.