[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2026-50811/freetype
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Jul 24 13:40:07 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d66bd124 by Salvatore Bonaccorso at 2026-07-24T14:37:22+02:00
Track fixed version for CVE-2026-50811/freetype
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -15593,7 +15593,7 @@ CVE-2026-53479 (DellPowerProtectData Domain, versions 7.7.1.0 through 8.7, LTS20
CVE-2026-51937 (An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitiv ...)
NOT-FOR-US: Oneblog
CVE-2026-50811 (An out-of-bounds read vulnerability exists in FreeType 2.14.3 and vers ...)
- - freetype <unfixed> (bug #1141704)
+ - freetype 2.14.3+dfsg-2 (bug #1141704)
[trixie] - freetype <not-affected> (Vulnerable code introduced later)
[bookworm] - freetype <not-affected> (TT_Get_Var_Design OOB read introduced in 2.14.0; shipped code uses safe coords[i]=0)
[bullseye] - freetype <not-affected> (TT_Get_Var_Design OOB read introduced in 2.14.0; shipped code uses safe coords[i]=0)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d66bd124638c1be45a80dba74af7e7a1117124ec
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d66bd124638c1be45a80dba74af7e7a1117124ec
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260724/35ff4c0c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list