Multiple vulnerabilities have been found in FreeType, one of which includes information leak.
| Package | media-libs/freetype on all architectures |
|---|---|
| Affected versions | < 2.14.3 |
| Unaffected versions | >= 2.14.3 |
FreeType is a software font engine that is designed to be small, efficient, highly customizable, and portable while capable of producing high-quality output (glyph images).
Multiple vulnerabilities have been discovered in FreeType. Please review the CVE identifiers referenced below for details.
One of the possible outcomes allows for an out-of-bounds read. Please review the referenced CVE identifiers for details.
There is no known workaround at this time.
All FreeType users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=media-libs/freetype-2.14.3"