Opened 7 months ago

Closed 6 months ago

#23028 closed enhancement (fixed)

freetype freetype-doc-2.14.3

Reported by: Bruce Dubbs Owned by: zeckma
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (7)

comment:1 by Joe Locash, 7 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:2 by Joe Locash, 7 months ago

Priority: normal → elevated
CHANGES BETWEEN 2.14.2 and 2.14.3 (2026-Mar-22)

  I. IMPORTANT BUG FIXES

  - A bunch of potential security problems have been found.  All users
    should update.


  II. MISCELLANEOUS

  - If configuration option `TT_CONFIG_OPTION_GPOS_KERNING` is active,
    GPOS-based kerning could miss some  value pairs (bug introduced in
    version 2.14.0).

Fixed at bb4f671f48.

I bumped this to elevated and leaving open because I don't know what the "potential security problems" are.

comment:3 by Douglas R. Reno, 7 months ago

When I asked about it for 2.14.2, I was told that there were several memory safety problems fixed. I suspect the same is probably true for 2.14.3, so let's note that while there are no CVEs assigned, this update does fix several potentially exploitable memory safety problems.

comment:4 by zeckma, 7 months ago

Owner: changed from Joe Locash to zeckma
Status: assigned → new

I'll handle the SA. I'll collect a little bit more information before filing it.

comment:5 by zeckma, 7 months ago

Status: new → assigned

comment:6 by Douglas R. Reno, 6 months ago

A brief review of ​https://gitlab.freedesktop.org/freetype/freetype/-/commits/VER-2-14-3 shows stack overflows, memory leaks, and some boundary problem fixes. I'll mention that in the advisory though there are no CVEs.

comment:7 by Douglas R. Reno, 6 months ago

Resolution: → fixed
Status: assigned → closed

SA-13.0-024 issued

Note: See TracTickets for help on using tickets.