Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
|
|
|
|
|
|
|
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
|
|
|
|
Become a Partner and License Our Database or Notification Service
|
|
|
|
|
|
|
|
|
|
|
|
|
(Red Hat Issues Fix for FreeType) Apple iOS Bugs Let Remote Users Execute Arbitrary Code and Obtain Information and Let Local Users Bypass Authentication
|
|
SecurityTracker Alert ID: 1026330 |
|
SecurityTracker URL: http://securitytracker.com/id/1026330
|
|
CVE Reference:
CVE-2011-3439
(Links to External Site)
|
Date: Nov 16 2011
|
Impact:
Disclosure of system information, Execution of arbitrary code via network, User access via local system, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
|
Description:
Several vulnerabilities were reported in Apple iOS. A remote user can cause arbitrary code to be executed on the target user's system. A physically local user can bypass authentication. A remote user can obtain potentially sensitive information. FreeType is affected by one vulnerability.
A remote user can create a specially crafted FreeType font that, when loaded by the target user, will execute arbitrary code on the target user's system [CVE-2011-3439].
A remote user can create specially crafted HTML that, when loaded by the target user, will cause libinfo to disclose potentially sensitive information via DNS name lookups [CVE-2011-3441]. Erling Ellingsen of Facebook and Per Johansson of Blocket AB reported this vulnerability.
A physically local user can open an iPad 2 Smart Cover while the device is confirming power off in the locked state to bypass the authentication passcode request [CVE-2011-3440]. The user cannot launch apps or access data protected by Data Protection.
|
Impact:
A remote user can create content that, when loaded by the target user, will execute arbitrary code on or obtain potentially sensitive information from the target user's system.
A physically local user can bypass the iPad 2 authentication passcode request in certain cases.
|
Solution:
Red Hat has issued a fix for CVE-2011-3439 for FreeType.
The Red Hat advisory is available at:
https://rhn.redhat.com/errata/RHSA-2011-1455.html
|
Cause:
Access control error
|
Underlying OS:
Linux (Red Hat Enterprise)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Wed, 16 Nov 2011 23:12:24 +0000
Subject: [RHSA-2011:1455-01] Important: freetype security update
|
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
=====================================================================
Red Hat Security Advisory
Synopsis: Important: freetype security update
Advisory ID: RHSA-2011:1455-01
Product: Red Hat Enterprise Linux
Advisory URL: https://rhn.redhat.com/errata/RHSA-2011-1455.html
Issue date: 2011-11-16
CVE Names: CVE-2011-3439
=====================================================================
1. Summary:
Updated freetype packages that fix multiple security issues are now
available for Red Hat Enterprise Linux 4, 5, and 6.
The Red Hat Security Response Team has rated this update as having
important security impact. A Common Vulnerability Scoring System (CVSS)
base score, which gives a detailed severity rating, is available from the
CVE link in the References section.
2. Relevant releases/architectures:
RHEL Desktop Workstation (v. 5 client) - i386, x86_64
Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64
Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64
Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux HPC Node (v. 6) - x86_64
Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64
Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64
Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64
3. Description:
FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. The freetype packages for Red Hat Enterprise Linux 4 provide
both the FreeType 1 and FreeType 2 font engines. The freetype packages for
Red Hat Enterprise Linux 5 and 6 provide only the FreeType 2 font engine.
Multiple input validation flaws were found in the way FreeType processed
CID-keyed fonts. If a specially-crafted font file was loaded by an
application linked against FreeType, it could cause the application to
crash or, potentially, execute arbitrary code with the privileges of the
user running the application. (CVE-2011-3439)
Note: These issues only affected the FreeType 2 font engine.
Users are advised to upgrade to these updated packages, which contain a
backported patch to correct these issues. The X server must be restarted
(log out, then log back in) for this update to take effect.
4. Solution:
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.
This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/kb/docs/DOC-11259
5. Bugs fixed (http://bugzilla.redhat.com/):
753799 - CVE-2011-3439 freetype: Multiple security flaws when loading CID-keyed Type 1 fonts
6. Package List:
Red Hat Enterprise Linux AS version 4:
Source:
ftp://updates.redhat.com/enterprise/4AS/en/os/SRPMS/freetype-2.1.9-21.el4.src.rpm
i386:
freetype-2.1.9-21.el4.i386.rpm
freetype-debuginfo-2.1.9-21.el4.i386.rpm
freetype-demos-2.1.9-21.el4.i386.rpm
freetype-devel-2.1.9-21.el4.i386.rpm
freetype-utils-2.1.9-21.el4.i386.rpm
ia64:
freetype-2.1.9-21.el4.i386.rpm
freetype-2.1.9-21.el4.ia64.rpm
freetype-debuginfo-2.1.9-21.el4.i386.rpm
freetype-debuginfo-2.1.9-21.el4.ia64.rpm
freetype-demos-2.1.9-21.el4.ia64.rpm
freetype-devel-2.1.9-21.el4.ia64.rpm
freetype-utils-2.1.9-21.el4.ia64.rpm
ppc:
freetype-2.1.9-21.el4.ppc.rpm
freetype-2.1.9-21.el4.ppc64.rpm
freetype-debuginfo-2.1.9-21.el4.ppc.rpm
freetype-debuginfo-2.1.9-21.el4.ppc64.rpm
freetype-demos-2.1.9-21.el4.ppc.rpm
freetype-devel-2.1.9-21.el4.ppc.rpm
freetype-utils-2.1.9-21.el4.ppc.rpm
s390:
freetype-2.1.9-21.el4.s390.rpm
freetype-debuginfo-2.1.9-21.el4.s390.rpm
freetype-demos-2.1.9-21.el4.s390.rpm
freetype-devel-2.1.9-21.el4.s390.rpm
freetype-utils-2.1.9-21.el4.s390.rpm
s390x:
freetype-2.1.9-21.el4.s390.rpm
freetype-2.1.9-21.el4.s390x.rpm
freetype-debuginfo-2.1.9-21.el4.s390.rpm
freetype-debuginfo-2.1.9-21.el4.s390x.rpm
freetype-demos-2.1.9-21.el4.s390x.rpm
freetype-devel-2.1.9-21.el4.s390x.rpm
freetype-utils-2.1.9-21.el4.s390x.rpm
x86_64:
freetype-2.1.9-21.el4.i386.rpm
freetype-2.1.9-21.el4.x86_64.rpm
freetype-debuginfo-2.1.9-21.el4.i386.rpm
freetype-debuginfo-2.1.9-21.el4.x86_64.rpm
freetype-demos-2.1.9-21.el4.x86_64.rpm
freetype-devel-2.1.9-21.el4.x86_64.rpm
freetype-utils-2.1.9-21.el4.x86_64.rpm
Red Hat Enterprise Linux Desktop version 4:
Source:
ftp://updates.redhat.com/enterprise/4Desktop/en/os/SRPMS/freetype-2.1.9-21.el4.src.rpm
i386:
freetype-2.1.9-21.el4.i386.rpm
freetype-debuginfo-2.1.9-21.el4.i386.rpm
freetype-demos-2.1.9-21.el4.i386.rpm
freetype-devel-2.1.9-21.el4.i386.rpm
freetype-utils-2.1.9-21.el4.i386.rpm
x86_64:
freetype-2.1.9-21.el4.i386.rpm
freetype-2.1.9-21.el4.x86_64.rpm
freetype-debuginfo-2.1.9-21.el4.i386.rpm
freetype-debuginfo-2.1.9-21.el4.x86_64.rpm
freetype-demos-2.1.9-21.el4.x86_64.rpm
freetype-devel-2.1.9-21.el4.x86_64.rpm
freetype-utils-2.1.9-21.el4.x86_64.rpm
Red Hat Enterprise Linux ES version 4:
Source:
ftp://updates.redhat.com/enterprise/4ES/en/os/SRPMS/freetype-2.1.9-21.el4.src.rpm
i386:
freetype-2.1.9-21.el4.i386.rpm
freetype-debuginfo-2.1.9-21.el4.i386.rpm
freetype-demos-2.1.9-21.el4.i386.rpm
freetype-devel-2.1.9-21.el4.i386.rpm
freetype-utils-2.1.9-21.el4.i386.rpm
ia64:
freetype-2.1.9-21.el4.i386.rpm
freetype-2.1.9-21.el4.ia64.rpm
freetype-debuginfo-2.1.9-21.el4.i386.rpm
freetype-debuginfo-2.1.9-21.el4.ia64.rpm
freetype-demos-2.1.9-21.el4.ia64.rpm
freetype-devel-2.1.9-21.el4.ia64.rpm
freetype-utils-2.1.9-21.el4.ia64.rpm
x86_64:
freetype-2.1.9-21.el4.i386.rpm
freetype-2.1.9-21.el4.x86_64.rpm
freetype-debuginfo-2.1.9-21.el4.i386.rpm
freetype-debuginfo-2.1.9-21.el4.x86_64.rpm
freetype-demos-2.1.9-21.el4.x86_64.rpm
freetype-devel-2.1.9-21.el4.x86_64.rpm
freetype-utils-2.1.9-21.el4.x86_64.rpm
Red Hat Enterprise Linux WS version 4:
Source:
ftp://updates.redhat.com/enterprise/4WS/en/os/SRPMS/freetype-2.1.9-21.el4.src.rpm
i386:
freetype-2.1.9-21.el4.i386.rpm
freetype-debuginfo-2.1.9-21.el4.i386.rpm
freetype-demos-2.1.9-21.el4.i386.rpm
freetype-devel-2.1.9-21.el4.i386.rpm
freetype-utils-2.1.9-21.el4.i386.rpm
ia64:
freetype-2.1.9-21.el4.i386.rpm
freetype-2.1.9-21.el4.ia64.rpm
freetype-debuginfo-2.1.9-21.el4.i386.rpm
freetype-debuginfo-2.1.9-21.el4.ia64.rpm
freetype-demos-2.1.9-21.el4.ia64.rpm
freetype-devel-2.1.9-21.el4.ia64.rpm
freetype-utils-2.1.9-21.el4.ia64.rpm
x86_64:
freetype-2.1.9-21.el4.i386.rpm
freetype-2.1.9-21.el4.x86_64.rpm
freetype-debuginfo-2.1.9-21.el4.i386.rpm
freetype-debuginfo-2.1.9-21.el4.x86_64.rpm
freetype-demos-2.1.9-21.el4.x86_64.rpm
freetype-devel-2.1.9-21.el4.x86_64.rpm
freetype-utils-2.1.9-21.el4.x86_64.rpm
Red Hat Enterprise Linux Desktop (v. 5 client):
Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Client/en/os/SRPMS/freetype-2.2.1-28.el5_7.2.src.rpm
i386:
freetype-2.2.1-28.el5_7.2.i386.rpm
freetype-debuginfo-2.2.1-28.el5_7.2.i386.rpm
x86_64:
freetype-2.2.1-28.el5_7.2.i386.rpm
freetype-2.2.1-28.el5_7.2.x86_64.rpm
freetype-debuginfo-2.2.1-28.el5_7.2.i386.rpm
freetype-debuginfo-2.2.1-28.el5_7.2.x86_64.rpm
RHEL Desktop Workstation (v. 5 client):
Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Client/en/os/SRPMS/freetype-2.2.1-28.el5_7.2.src.rpm
i386:
freetype-debuginfo-2.2.1-28.el5_7.2.i386.rpm
freetype-demos-2.2.1-28.el5_7.2.i386.rpm
freetype-devel-2.2.1-28.el5_7.2.i386.rpm
x86_64:
freetype-debuginfo-2.2.1-28.el5_7.2.i386.rpm
freetype-debuginfo-2.2.1-28.el5_7.2.x86_64.rpm
freetype-demos-2.2.1-28.el5_7.2.x86_64.rpm
freetype-devel-2.2.1-28.el5_7.2.i386.rpm
freetype-devel-2.2.1-28.el5_7.2.x86_64.rpm
Red Hat Enterprise Linux (v. 5 server):
Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Server/en/os/SRPMS/freetype-2.2.1-28.el5_7.2.src.rpm
i386:
freetype-2.2.1-28.el5_7.2.i386.rpm
freetype-debuginfo-2.2.1-28.el5_7.2.i386.rpm
freetype-demos-2.2.1-28.el5_7.2.i386.rpm
freetype-devel-2.2.1-28.el5_7.2.i386.rpm
ia64:
freetype-2.2.1-28.el5_7.2.i386.rpm
freetype-2.2.1-28.el5_7.2.ia64.rpm
freetype-debuginfo-2.2.1-28.el5_7.2.i386.rpm
freetype-debuginfo-2.2.1-28.el5_7.2.ia64.rpm
freetype-demos-2.2.1-28.el5_7.2.ia64.rpm
freetype-devel-2.2.1-28.el5_7.2.ia64.rpm
ppc:
freetype-2.2.1-28.el5_7.2.ppc.rpm
freetype-2.2.1-28.el5_7.2.ppc64.rpm
freetype-debuginfo-2.2.1-28.el5_7.2.ppc.rpm
freetype-debuginfo-2.2.1-28.el5_7.2.ppc64.rpm
freetype-demos-2.2.1-28.el5_7.2.ppc.rpm
freetype-devel-2.2.1-28.el5_7.2.ppc.rpm
freetype-devel-2.2.1-28.el5_7.2.ppc64.rpm
s390x:
freetype-2.2.1-28.el5_7.2.s390.rpm
freetype-2.2.1-28.el5_7.2.s390x.rpm
freetype-debuginfo-2.2.1-28.el5_7.2.s390.rpm
freetype-debuginfo-2.2.1-28.el5_7.2.s390x.rpm
freetype-demos-2.2.1-28.el5_7.2.s390x.rpm
freetype-devel-2.2.1-28.el5_7.2.s390.rpm
freetype-devel-2.2.1-28.el5_7.2.s390x.rpm
x86_64:
freetype-2.2.1-28.el5_7.2.i386.rpm
freetype-2.2.1-28.el5_7.2.x86_64.rpm
freetype-debuginfo-2.2.1-28.el5_7.2.i386.rpm
freetype-debuginfo-2.2.1-28.el5_7.2.x86_64.rpm
freetype-demos-2.2.1-28.el5_7.2.x86_64.rpm
freetype-devel-2.2.1-28.el5_7.2.i386.rpm
freetype-devel-2.2.1-28.el5_7.2.x86_64.rpm
Red Hat Enterprise Linux Desktop (v. 6):
Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Client/en/os/SRPMS/freetype-2.3.11-6.el6_1.8.src.rpm
i386:
freetype-2.3.11-6.el6_1.8.i686.rpm
freetype-debuginfo-2.3.11-6.el6_1.8.i686.rpm
x86_64:
freetype-2.3.11-6.el6_1.8.i686.rpm
freetype-2.3.11-6.el6_1.8.x86_64.rpm
freetype-debuginfo-2.3.11-6.el6_1.8.i686.rpm
freetype-debuginfo-2.3.11-6.el6_1.8.x86_64.rpm
Red Hat Enterprise Linux Desktop Optional (v. 6):
Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Client/en/os/SRPMS/freetype-2.3.11-6.el6_1.8.src.rpm
i386:
freetype-debuginfo-2.3.11-6.el6_1.8.i686.rpm
freetype-demos-2.3.11-6.el6_1.8.i686.rpm
freetype-devel-2.3.11-6.el6_1.8.i686.rpm
x86_64:
freetype-debuginfo-2.3.11-6.el6_1.8.i686.rpm
freetype-debuginfo-2.3.11-6.el6_1.8.x86_64.rpm
freetype-demos-2.3.11-6.el6_1.8.x86_64.rpm
freetype-devel-2.3.11-6.el6_1.8.i686.rpm
freetype-devel-2.3.11-6.el6_1.8.x86_64.rpm
Red Hat Enterprise Linux HPC Node (v. 6):
Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6ComputeNode/en/os/SRPMS/freetype-2.3.11-6.el6_1.8.src.rpm
x86_64:
freetype-2.3.11-6.el6_1.8.i686.rpm
freetype-2.3.11-6.el6_1.8.x86_64.rpm
freetype-debuginfo-2.3.11-6.el6_1.8.i686.rpm
freetype-debuginfo-2.3.11-6.el6_1.8.x86_64.rpm
Red Hat Enterprise Linux HPC Node Optional (v. 6):
Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6ComputeNode/en/os/SRPMS/freetype-2.3.11-6.el6_1.8.src.rpm
x86_64:
freetype-debuginfo-2.3.11-6.el6_1.8.i686.rpm
freetype-debuginfo-2.3.11-6.el6_1.8.x86_64.rpm
freetype-demos-2.3.11-6.el6_1.8.x86_64.rpm
freetype-devel-2.3.11-6.el6_1.8.i686.rpm
freetype-devel-2.3.11-6.el6_1.8.x86_64.rpm
Red Hat Enterprise Linux Server (v. 6):
Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Server/en/os/SRPMS/freetype-2.3.11-6.el6_1.8.src.rpm
i386:
freetype-2.3.11-6.el6_1.8.i686.rpm
freetype-debuginfo-2.3.11-6.el6_1.8.i686.rpm
freetype-devel-2.3.11-6.el6_1.8.i686.rpm
ppc64:
freetype-2.3.11-6.el6_1.8.ppc.rpm
freetype-2.3.11-6.el6_1.8.ppc64.rpm
freetype-debuginfo-2.3.11-6.el6_1.8.ppc.rpm
freetype-debuginfo-2.3.11-6.el6_1.8.ppc64.rpm
freetype-devel-2.3.11-6.el6_1.8.ppc.rpm
freetype-devel-2.3.11-6.el6_1.8.ppc64.rpm
s390x:
freetype-2.3.11-6.el6_1.8.s390.rpm
freetype-2.3.11-6.el6_1.8.s390x.rpm
freetype-debuginfo-2.3.11-6.el6_1.8.s390.rpm
freetype-debuginfo-2.3.11-6.el6_1.8.s390x.rpm
freetype-devel-2.3.11-6.el6_1.8.s390.rpm
freetype-devel-2.3.11-6.el6_1.8.s390x.rpm
x86_64:
freetype-2.3.11-6.el6_1.8.i686.rpm
freetype-2.3.11-6.el6_1.8.x86_64.rpm
freetype-debuginfo-2.3.11-6.el6_1.8.i686.rpm
freetype-debuginfo-2.3.11-6.el6_1.8.x86_64.rpm
freetype-devel-2.3.11-6.el6_1.8.i686.rpm
freetype-devel-2.3.11-6.el6_1.8.x86_64.rpm
Red Hat Enterprise Linux Server Optional (v. 6):
Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Server/en/os/SRPMS/freetype-2.3.11-6.el6_1.8.src.rpm
i386:
freetype-debuginfo-2.3.11-6.el6_1.8.i686.rpm
freetype-demos-2.3.11-6.el6_1.8.i686.rpm
ppc64:
freetype-debuginfo-2.3.11-6.el6_1.8.ppc64.rpm
freetype-demos-2.3.11-6.el6_1.8.ppc64.rpm
s390x:
freetype-debuginfo-2.3.11-6.el6_1.8.s390x.rpm
freetype-demos-2.3.11-6.el6_1.8.s390x.rpm
x86_64:
freetype-debuginfo-2.3.11-6.el6_1.8.x86_64.rpm
freetype-demos-2.3.11-6.el6_1.8.x86_64.rpm
Red Hat Enterprise Linux Workstation (v. 6):
Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Workstation/en/os/SRPMS/freetype-2.3.11-6.el6_1.8.src.rpm
i386:
freetype-2.3.11-6.el6_1.8.i686.rpm
freetype-debuginfo-2.3.11-6.el6_1.8.i686.rpm
freetype-devel-2.3.11-6.el6_1.8.i686.rpm
x86_64:
freetype-2.3.11-6.el6_1.8.i686.rpm
freetype-2.3.11-6.el6_1.8.x86_64.rpm
freetype-debuginfo-2.3.11-6.el6_1.8.i686.rpm
freetype-debuginfo-2.3.11-6.el6_1.8.x86_64.rpm
freetype-devel-2.3.11-6.el6_1.8.i686.rpm
freetype-devel-2.3.11-6.el6_1.8.x86_64.rpm
Red Hat Enterprise Linux Workstation Optional (v. 6):
Source:
ftp://ftp.redhat.com/pub/redhat/linux/enterprise/6Workstation/en/os/SRPMS/freetype-2.3.11-6.el6_1.8.src.rpm
i386:
freetype-debuginfo-2.3.11-6.el6_1.8.i686.rpm
freetype-demos-2.3.11-6.el6_1.8.i686.rpm
x86_64:
freetype-debuginfo-2.3.11-6.el6_1.8.x86_64.rpm
freetype-demos-2.3.11-6.el6_1.8.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/#package
7. References:
https://www.redhat.com/security/data/cve/CVE-2011-3439.html
https://access.redhat.com/security/updates/classification/#important
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2011 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (GNU/Linux)
iD8DBQFOxELiXlSAg2UNWIIRAmg3AJ97Gr0i8TaFnRSHpygUtgufIIvBsgCfQ/lt
9X4xr8MjwZa5fRg3cRkFSu4=
=DgiA
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce
|
|
Go to the Top of This SecurityTracker Archive Page
|