FreeType 2.10.4 Rushed Out As Emergency Security Release
The FreeType text rendering library is out with version 2.10.4 today as an important security update.
Public entries on the CVE-2020-15999 vulnerability aren't yet loading but it's in regards to a heap buffer overflow in FreeType's handling of PNG bitmaps. The vulnerability has been around since FreeType 2.6.
The FreeType.org project site simply reads, "This is an emergency release, fixing a severe vulnerability in embedded PNG bitmap handling...All users should update immediately."
This important security fix is the only listed change since FreeType 2.10.3.
Public entries on the CVE-2020-15999 vulnerability aren't yet loading but it's in regards to a heap buffer overflow in FreeType's handling of PNG bitmaps. The vulnerability has been around since FreeType 2.6.
The FreeType.org project site simply reads, "This is an emergency release, fixing a severe vulnerability in embedded PNG bitmap handling...All users should update immediately."
This important security fix is the only listed change since FreeType 2.10.3.
25 Comments