The following defect(s) have been fixed in this cumulative patch for the Wind River freetype:
WIND00230116 Security Advisory - FreeType - CVE-2010-3053
WIND00232301 Security Advisory - freetype - CVE-2010-3054
WIND00234502 Security Advisory - freetype - CVE-2010-3311
WIND00237559 Security Advisory - freetype - CVE-2010-3814
WIND00237563 Security Advisory - freetype - CVE-2010-3855
-----------------------------------------------------------------------------------------------------------------------------------------------
Change List:
/layers/wrll-userspace/graphics/dist/freetype/Makefile
/layers/wrll-userspace/graphics/dist/freetype/freetype.spec
/layers/wrll-userspace/graphics/dist/freetype/patches/freetype-2.3.5-CVE-2010-3053.patch
/layers/wrll-userspace/graphics/dist/freetype/patches/freetype-2.3.9-CVE-2010-3054.patch
/layers/wrll-userspace/graphics/dist/freetype/patches/freetype-2.2.1-CVE-2010-3311.patch
/layers/wrll-userspace/graphics/dist/freetype/patches/freetype-2.3.5-CVE-2010-3814.patch
/layers/wrll-userspace/graphics/dist/freetype/patches/freetype-2.3.5-CVE-2010-3855.patch
1. Unzip this patch under [install_dir]/updates.
2. From the [install_dir]/updates directory, run the command "../maintenance/wrInstaller/x86-linux2/wrInstaller".
3. Follow the instructions for installing the point patch.
4. This is a source only patch so you will have to rebuild the
freetype package. This can be done by executing the command "make
-C build freetype.distclean" followed by "make -C build
freetype.rebuild"
5. Run "make fs" next
6. Upload the kernel and rootfs into the target and boot it up.
DATE: 22 Oct 2010
REVISION: Add file WRL_4_0-layers-wrll_userspace_graphics-tgt-freetype-20101020-spin1.zip and includes fix to defect WIND00230116