Multiple vulnerabilities were discovered in FreeType's Printer
Font Binary (PFB) font-file format parser. If a user were to load a
carefully crafted font file with a program linked against FreeType, it
could cause the application to crash or potentially execute arbitrary
code (CVE-2008-1806, CVE-2008-1807, CVE-2008-1808).
The updated packages have been patched to prevent this issue.
Update:
The patches used to correct the problem on Corporate Server 4.0 and
Corporate 3.0 contained a problem where certain fonts would not be
displayed and would cause applications, such as drakfont, to crash.
This update corrects the regression.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2008-1806
http://cve.mitre.org/cgi-bin/cvename.cg ... -2008-1807
http://cve.mitre.org/cgi-bin/cvename.cg ... -2008-1808
https://qa.mandriva.com/45350
_______________________________________________________________________