Vulnerability In Font Processing Library Affects Linux, OpenOffice, Firefox (softpedia.com)
An anonymous reader writes: If an application can embed fonts with special characters, then it's probably using the Graphite font processing library. This library has several security issues which an attacker can leverage to take control of your OS via remote code execution scenarios. The simple attack would be to deliver a malicious font via a Web page's CSS. The malformed font loads in Firefox, triggers the RCE exploit, and voila, your PC has a hole inside through which malware can creep in.
Good morning Timmy boy!
Not on to important matters.... NEWS FLASH! RED ALERT! THIS JUST IN! Software has security vulnerabilities.
I'm shocked, shocked to find that gambling is going on in here!
How can something like this happen with many eyes looking at it constantly?
I'll stick with Windows where things just work.
Known Vulnerable Versions:
Libgraphite 2-1.2.4
Firefox 31-42
source: http://blog.talosintel.com/2016/02/vulnerability-spotlight-libgraphite.html
If only systems and programming languages had been developed that eradicated an entire class of software bugs.
Can I haz SELinux + grsecurity in all major distributions by default plz.
NB: The message above might reflect my opinion right now, but not necessarily tomorrow or next year.
This proves yet again that our only real option is to use the Rust programming language when writing software. Unlike pretty much every other programming language out there, Rust has a extensive code of conduct and a moderation team to enforce that code of conduct. Together these prevent racism, sexism, homophobia and intolerance from affecting software written in Rust.
libgraphite is used by libreoffice, grcompiler, texlive-binaries, fonts-sil-padauk.
I have no doubt a more forward looking distro like Fedora or Arch will have more applications that include libgraphite/silgraphite as a dependency. Sadly I can't verify dependants from here: https://apps.fedoraproject.org/packages/graphite2/
Just desactivate the graphite thing in firefox (if you are using one of the vulnerable verions, 11-42) and you are done.
I like the font they used in the article. Very creative, especially how it included photos of my kids and parts of the social security number
What a fucking bad solution. Like the goddamn summary says, other applications are affected. Disabling this in Firefox doesn't do a fucking thing to fix OpenOffice, for instance!
YOU NEED TO UPGRADE THE BUGGY LIBRARY!
YOU NEED TO UPGRADE THE BUGGY LIBRARY!
YOU NEED TO UPGRADE THE BUGGY LIBRARY!
I saw this once at Reweb a former client of mine: They were using a font... I forgot the name now... But it was bad as fuck because it was not standard. So, I think everywhere Google put it's finger may be being secretly exploited. Hmpf.
funny story
Whaaaaaaaaaaaaaaaaaaaaaa hahhahaha hahahhahahahahhahah
Haaaaaaaaaaaaaaaaa hahahahha hahahahaha hhahahahaaahaaahh
Haaaaaaaaaaaaaaaaaa hahhhaha hahhahahaha hahahahahahahaha
ROFL
all of you used $MY_FAVORITE_LANGUAGE which is better than $YOUR_FAVORITE_LANGUAGE. And then $MY_FAVORITE_BLOATED_ACCESS_CONTROL.
Yes, yes. Thankyouverymuch
If an application can embed fonts with special characters, then it's probably using the Graphite font processing library.
Unless it's a Windows, Mac OS or iOS app that uses the font processing built into the operating system. Which is like 99% of applications.
This is what happens.
This is why the Web sucks, we mix code and data, and people get owned.
FTA:
"The worst is an out-of-bounds read bug (CVE-2016-1521) that allows attackers to crash the system"
Err no. It'll crash the browser (or whichever userspace program is using the library). Thats a bit different to crashing the kernel.
Bring back the X Font Server and get off my lawn!
How can we blame this on systemd?
I haven't let web pages use different fonts for years. I use a font at a size on my browser that I find easy to read and I found a long time ago that people making pages were trying to change fonts and sizes to things that weren't as easy for me to read. This comes from people who think that they need to have absolute control of how everything is displayed on the page. That was never the intention of how the web was to work.
Is Pale Moon fixed? I don't see any mention of that.
We switched to Pale Moon and are now not having problems with the instability of Firefox when there are many windows and tabs open. Since Pale Moon is based on Firefox, most of the Firefox add-ons work.
In the past, Google paid Mozilla Foundation $300 million each year to make Google search the default search engine in Firefox. Google apparently didn't cause problems, even though it paid a shocking amount.
Now, I understand, Mozilla Foundation gets most of its money from Microsoft. Microsoft pays Yahoo. Yahoo pays Mozilla Foundation to make "Yahoo search" (actually mostly Microsoft Bing search) the default search engine in Firefox.
The Thunderbird and SeaMonkey Composer GUIs have been damaged, apparently deliberately. File saves in the newer versions of both ask for a new file name, and don't suggest the last one chosen. The damage was reported several months ago, but has not been fixed.
Is that another example of Microsoft's Embrace, Extend, Extinguish? People who feel forced away from Thunderbird may choose Microsoft software to replace it. Is that something Microsoft is trying to accomplish?
In my opinion, dishonest people should not be employed in management. In my opinion, the managers and members of the board of directors of both Microsoft and Mozilla Foundation who approved the dishonesty of sneakily re-configuring Mozilla Foundation products should be immediately fired, and not allowed to have management positions in the future.
Mozilla Foundation may be desperate now that it has lost the incredible amount of money paid by Google.
A few of the many, many articles about abuse by Microsoft:
Microsoft has no plans to tell us what's in Windows patches. Each update is a black box, and it's going to stay that way.
Leaks show that Microsoft writes release notes, so why can't it publish them? The lack of documentation of Windows' updates is a baffling move on Microsoft's part.
Microsoft's Software is Malware. Malware means software designed to function in ways that mistreat or harm the user.
How Can Any Company Ever Trust Microsoft Again?
NSA Backdoor Exploit in Windows 8 Uncovered
Microsoft Gave the NSA Direct Backdoor Access to Outlook, Skype
Microsoft [lack of] Privacy Statement
Here's how to Block Windows 10 "Spying"
Another report about Justice Scalia: Cibolo Creek Ranch owner recalls Scaliaâ(TM)s last hours in Texas.
The owner of the ranch is John Poindexter. He was a National Security Advisor. He was convicted in April 1990 of multiple felonies as a result of his actions in the Iran-Contra affair, but his convictions were reversed on appeal in 1991.
How did he become so rich?
That FINE reliable Open SORES code! Solid, dependable, bulletproof and bug free? No way. Not with noobs that make it. Hahahahahahahaha!
https://xkcd.com/327/
More seriously, there is usually no need and no point to embedding fonts. If it's not renderable in good old LANG=POSIX ASCII 7-bit flat text, or it has images and needs to include them in a plain HTML document, but can't be rendered with prettification and excessive layout, then it's a *bad document* and should be sent back to its author to learn how to write legible English in a legibal format.
If the document is not in English, OK, I can see a use for more formatting. Mathematical equations and chemistry notation, also OK if needed. But that is the *only* excuse for not using graphics free presentation. A QA checklist does *NOT NEED 37 fonts!!!*.
Can lead of your system being pw0ned!
Damned Micro$oft!!!!!!!!!!!!.... ...OH ... WAIT....
*** Suerte a todos y Feliz dia!
Affected. It's already fixed.
The way I handle such issues is to look at the big picture. I don't know exactly what is happening with Microsoft and Windows, but there are many, many reports that indicate crazy things are happening.
Another example: I don't know what happened on 9/11/2001 at the World Trade Center, but it is interesting that Marvin P. Bush, the president's younger brother, was a principal in a company called Securacom that provided security for the World Trade Center.
The domination we are seeing is destructive toward the lives of those who do it, in the kind of way that alcoholism is not a solution to problems, but degrades the lives of alcoholics.
Open Sores is perfect softwares!
Wow! Moderated up to +4, now at 0.
That's avoidance, not logic. There are many, many, many articles about abuse by Microsoft. Whether or not you like what I said, or the articles I chose, there is an issue.
As I said above: The domination we are seeing is destructive toward the lives of those who do it, in the kind of way that alcoholism is not a solution to problems, but degrades the lives of alcoholics.
Don't be dishonest toward yourselves. Deal with conflicts, don't avoid them.
I can find no workarounds for Chrome - posted in the chrome forum. Just wondered if anyone else was concerned enough to figure out how to disable it in Chrome until the library is updated. /opt/google/chrome/chrome: /usr/lib64/libgraphite2.so.3 (0x00007fb69a34e000)
From ldd output of
libgraphite2.so.3 =>
Redundancy is good; triple redundancy is twice as good! - Me.