Vulnerability Bulletins

DSA-3644 fontconfig - security update

   
Affected software Debian
 
Tobias Stoeckmann discovered that cache files are insufficientlyvalidated in fontconfig, a generic font configuration library. Anattacker can trigger arbitrary free() calls, which in turn allows doublefree attacks and therefore arbitrary code execution. In combination withsetuid binaries using crafted cache files, this could allow privilegeescalation.

More info:

https://www.debian.org/security/2016/dsa-3644