FreeType 2.10.4 Rushed Out As Emergency Security Release

Written by Michael Larabel in Free Software on 20 October 2020 at 05:18 AM EDT. 25 Comments
FREE SOFTWARE
The FreeType text rendering library is out with version 2.10.4 today as an important security update.

Public entries on the CVE-2020-15999 vulnerability aren't yet loading but it's in regards to a heap buffer overflow in FreeType's handling of PNG bitmaps. The vulnerability has been around since FreeType 2.6.

The FreeType.org project site simply reads, "This is an emergency release, fixing a severe vulnerability in embedded PNG bitmap handling...All users should update immediately."

This important security fix is the only listed change since FreeType 2.10.3.
Related News
About The Author
Michael Larabel

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.

Popular News This Week