Package "libxfont"
| Name: |
libxfont
|
Description: |
This package is just an umbrella for a group of other packages,
it has no description. Description samples from packages in group:
- X11 font rasterisation library (development headers)
- X11 font rasterisation library
|
| Latest version: |
1:2.0.6-1+deb13u1build0.24.04.2 |
| Release: |
noble (24.04) |
| Level: |
security |
| Repository: |
main |
Links
Other versions of "libxfont" in Noble
Packages in group
Deleted packages are displayed in grey.
Changelog
|
libxfont (1:2.0.6-1+deb13u1build0.24.04.2) noble-security; urgency=medium
* Manage the security patches with quilt. The same fixes as
1:2.0.6-1+deb13u1 are applied, but as tracked patches rather than edits
made directly to the upstream sources.
- debian/patches/CVE-2026-56001.patch,
debian/patches/CVE-2026-56002.patch,
debian/patches/CVE-2026-56003.patch: add the patch files, carrying the
CVE-2026-56001, CVE-2026-56002 and CVE-2026-56003 fixes that
1:2.0.6-1+deb13u1 applied directly to the upstream sources.
- debian/patches/series: list the three patches (was "# placeholder").
* debian/patches/CVE-2026-56001.patch: additionally convert the
"Couldn't allocate bitmaps" fprintf() to %zu instead of %d.
-- John Breton <email address hidden> Thu, 16 Jul 2026 07:44:32 -0400
|
| CVE-2026-56001 |
A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the |
| CVE-2026-56002 |
A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to exec |
| CVE-2026-56003 |
A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXf |
|
About
-
Send Feedback to @ubuntu_updates