New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 594972 link

Starred by 2 users

Issue metadata

Status: Fixed
Owner:
Closed: Mar 2017
Cc:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 1
Type: Bug

Blocking:
issue 599864
issue 599865
issue 610644



Sign in to add a comment

update third_party/freetype2 to 2.6.3 or higher

Project Member Reported by mmoroz@chromium.org, Mar 15 2016

Issue description

Current version of freetype library under https://code.google.com/p/chromium/codesearch#chromium/src/third_party/freetype2/ is 2.4.8 which has been released in 2011. This version is exteremly out of date and contains more than 50+ known security bugs. Some references are here: https://codereview.chromium.org/1776323002/

If this software isn't used in Chromium and an update doesn't make sense, please consider a possibility to remove it from repository.
 
Blocking: 599864
Blocking: 599865

Comment 3 by mmoroz@chromium.org, May 24 2016

Blocking: 610644
Labels: Security_Impact-None

Comment 5 by mmoroz@google.com, May 30 2016

Summary: update third_party/freetype2 to 2.6.3 or higher (was: update third_party/freetype2 to 2.6.3 or another of the latests versions)

Comment 6 by mmoroz@chromium.org, Jun 30 2016

I've made an attempt to roll version 2.6.3, now waiting for trybots result: https://codereview.chromium.org/2113713002/

IIUC, the main point against the update is "We do not ship freetype to our users". 

Anyway, we want to keep our users safer. We should care about libraries which are used by Chrome even if we don't ship them. Fuzzing of up-to-date fretype2 version at ClusterFuzz is very important for that.
Status: Fixed (was: Untriaged)
This is now at 2.7.1+.
Project Member

Comment 8 by sheriffbot@chromium.org, Mar 21 2017

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Project Member

Comment 9 by sheriffbot@chromium.org, Jun 27 2017

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment