[hafqa] [hafqa] [Bug 3701] DSA-1635-1 freetype -- multiple vulnerabilities

From: bugzilla-daemon at maemo.org bugzilla-daemon at maemo.org
Date: Mon Sep 15 22:45:42 EEST 2008
https://bugs.maemo.org/show_bug.cgi?id=3701





------- Comment #2 from leif at sonic.net  2008-09-15 22:45 GMT+3 -------
(In reply to comment #1)
> This should be fairly low risk, two of these were about printer fonts, one
> about TTF and I don't see how anything loaded from the net would be run
> through freetype. It would first need remote exploit or user installing
> "malicious" font to the device.

Downloadable fonts aren't supported in Gecko, but they are in WebKit:
http://www.w3.org/TR/CSS2/fonts.html#referencing
http://webkit.org/blog/124/downloadable-fonts/


-- 
Configure bugmail: https://bugs.maemo.org/userprefs.cgi?tab=email
Replies to this email are NOT read, instead please add comments at
https://bugs.maemo.org/show_bug.cgi?id=3701
------- You are receiving this mail because: -------
You are the QA contact for the bug, or are watching the QA contact.

More information about the hafqa mailing list