[RHSA-2017:1793] graphite2 security update

Severity Important
Affected Packages 16
CVEs 8

Graphite2 is a project within SIL's Non-Roman Script Initiative and Language Software Development groups to provide rendering capabilities for complex non-Roman writing systems. Graphite can be used to create "smart fonts" capable of displaying writing systems with various complex behaviors. With respect to the Text Encoding Model, Graphite handles the "Rendering" aspect of writing system implementation.

The following packages have been upgraded to a newer upstream version: graphite2 (1.3.10).

Security Fix(es):

  • Various vulnerabilities have been discovered in Graphite2. An attacker able to trick an unsuspecting user into opening specially crafted font files in an application using Graphite2 could exploit these flaws to disclose potentially sensitive memory, cause an application crash, or, possibly, execute arbitrary code. (CVE-2017-7771, CVE-2017-7772, CVE-2017-7773, CVE-2017-7774, CVE-2017-7775, CVE-2017-7776, CVE-2017-7777, CVE-2017-7778)

Red Hat would like to thank the Mozilla project for reporting these issues. Upstream acknowledges Holger Fuhrmannek and Tyson Smith as the original reporters of these issues.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/redhat/graphite2?arch=x86_64&distro=redhat-7.3 redhat graphite2 < 1.3.10-1.el7_3 redhat-7.3 x86_64
Affected pkg:rpm/redhat/graphite2?arch=s390x&distro=redhat-7.3 redhat graphite2 < 1.3.10-1.el7_3 redhat-7.3 s390x
Affected pkg:rpm/redhat/graphite2?arch=s390&distro=redhat-7.3 redhat graphite2 < 1.3.10-1.el7_3 redhat-7.3 s390
Affected pkg:rpm/redhat/graphite2?arch=ppc64le&distro=redhat-7.3 redhat graphite2 < 1.3.10-1.el7_3 redhat-7.3 ppc64le
Affected pkg:rpm/redhat/graphite2?arch=ppc64&distro=redhat-7.3 redhat graphite2 < 1.3.10-1.el7_3 redhat-7.3 ppc64
Affected pkg:rpm/redhat/graphite2?arch=ppc&distro=redhat-7.3 redhat graphite2 < 1.3.10-1.el7_3 redhat-7.3 ppc
Affected pkg:rpm/redhat/graphite2?arch=i686&distro=redhat-7.3 redhat graphite2 < 1.3.10-1.el7_3 redhat-7.3 i686
Affected pkg:rpm/redhat/graphite2?arch=aarch64&distro=redhat-7.3 redhat graphite2 < 1.3.10-1.el7_3 redhat-7.3 aarch64
Affected pkg:rpm/redhat/graphite2-devel?arch=x86_64&distro=redhat-7.3 redhat graphite2-devel < 1.3.10-1.el7_3 redhat-7.3 x86_64
Affected pkg:rpm/redhat/graphite2-devel?arch=s390x&distro=redhat-7.3 redhat graphite2-devel < 1.3.10-1.el7_3 redhat-7.3 s390x
Affected pkg:rpm/redhat/graphite2-devel?arch=s390&distro=redhat-7.3 redhat graphite2-devel < 1.3.10-1.el7_3 redhat-7.3 s390
Affected pkg:rpm/redhat/graphite2-devel?arch=ppc64le&distro=redhat-7.3 redhat graphite2-devel < 1.3.10-1.el7_3 redhat-7.3 ppc64le
Affected pkg:rpm/redhat/graphite2-devel?arch=ppc64&distro=redhat-7.3 redhat graphite2-devel < 1.3.10-1.el7_3 redhat-7.3 ppc64
Affected pkg:rpm/redhat/graphite2-devel?arch=ppc&distro=redhat-7.3 redhat graphite2-devel < 1.3.10-1.el7_3 redhat-7.3 ppc
Affected pkg:rpm/redhat/graphite2-devel?arch=i686&distro=redhat-7.3 redhat graphite2-devel < 1.3.10-1.el7_3 redhat-7.3 i686
Affected pkg:rpm/redhat/graphite2-devel?arch=aarch64&distro=redhat-7.3 redhat graphite2-devel < 1.3.10-1.el7_3 redhat-7.3 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date