_______________________________________________________________________
Package : freetype2
Date : September 22, 2009
Affected: 2009.1
_______________________________________________________________________
Problem Description:
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote
attackers to execute arbitrary code via vectors related to large
values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c,
and (3) cff/cffload.c.
This update corrects the problem.
Update:
Correct a problem in the 2009.1 update of the lzw handling code.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-0946
_______________________________________________________________________