Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2020:4951 - Security Advisory
Issued:
2020-11-05
Updated:
2020-11-05

RHSA-2020:4951 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: freetype security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for freetype is now available for Red Hat Enterprise Linux 8.2 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

FreeType is a free, high-quality, portable font engine that can open and manage font files. FreeType loads, hints, and renders individual glyphs efficiently.

Security Fix(es):

  • freetype: Heap-based buffer overflow due to integer truncation in Load_SBit_Png (CVE-2020-15999)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

The X server must be restarted (log out, then log back in) for this update to take effect.

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.2 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.2 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.2 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.2 ppc64le
  • Red Hat Enterprise Linux Server - TUS 8.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.2 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.2 x86_64

Fixes

  • BZ - 1890210 - CVE-2020-15999 freetype: Heap-based buffer overflow due to integer truncation in Load_SBit_Png

CVEs

  • CVE-2020-15999

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.2

SRPM
freetype-2.9.1-4.el8_2.1.src.rpm SHA-256: 34de9c1c1147e0aa70260ca565bfd1e0e976dd97118c30dfe5c6587494df8d0b
x86_64
freetype-2.9.1-4.el8_2.1.i686.rpm SHA-256: 38352545adbea288b0ae3201de4a61553d374b238e5303a8027bba56b8a49034
freetype-2.9.1-4.el8_2.1.x86_64.rpm SHA-256: 82a03989bcdbc0583300604f0c69cbe0386a3d4e80eb886ead3e77e6a3a4ebc1
freetype-debuginfo-2.9.1-4.el8_2.1.i686.rpm SHA-256: 8b8e3b0b3f8befde359d055c88506aa81302fe088d30a046e723a2264b709a00
freetype-debuginfo-2.9.1-4.el8_2.1.x86_64.rpm SHA-256: cd81e0ec198303b460198152979a2f48d97d19f5ab3d50186d8e87dcffdd63b6
freetype-debugsource-2.9.1-4.el8_2.1.i686.rpm SHA-256: 72970800ddd3570c182b3d9a243739409d017413c487031ebb9097aaa8873abc
freetype-debugsource-2.9.1-4.el8_2.1.x86_64.rpm SHA-256: f953d1b4b6182543898e8c04c5688fe47ab172af3804b3d95974828fe9ce9107
freetype-demos-debuginfo-2.9.1-4.el8_2.1.i686.rpm SHA-256: 480f21152ffba45488439b989fb8cf0e70b997f656db11f92e339cafec9dfc64
freetype-demos-debuginfo-2.9.1-4.el8_2.1.x86_64.rpm SHA-256: 4080b2beeeb0e6274e59ce57d8ba25726f01a9c30e3aebd80cf95c7229c63d15
freetype-devel-2.9.1-4.el8_2.1.i686.rpm SHA-256: 0b43cfce0f9d7324a2a9936869beef3f131cfb809ec3e3c257301b4424ad0c0f
freetype-devel-2.9.1-4.el8_2.1.x86_64.rpm SHA-256: 9f1a90af056da580a04a8757995a05103aab755a3119d4ee35302efa04e53a7d

Red Hat Enterprise Linux Server - AUS 8.2

SRPM
freetype-2.9.1-4.el8_2.1.src.rpm SHA-256: 34de9c1c1147e0aa70260ca565bfd1e0e976dd97118c30dfe5c6587494df8d0b
x86_64
freetype-2.9.1-4.el8_2.1.i686.rpm SHA-256: 38352545adbea288b0ae3201de4a61553d374b238e5303a8027bba56b8a49034
freetype-2.9.1-4.el8_2.1.x86_64.rpm SHA-256: 82a03989bcdbc0583300604f0c69cbe0386a3d4e80eb886ead3e77e6a3a4ebc1
freetype-debuginfo-2.9.1-4.el8_2.1.i686.rpm SHA-256: 8b8e3b0b3f8befde359d055c88506aa81302fe088d30a046e723a2264b709a00
freetype-debuginfo-2.9.1-4.el8_2.1.x86_64.rpm SHA-256: cd81e0ec198303b460198152979a2f48d97d19f5ab3d50186d8e87dcffdd63b6
freetype-debugsource-2.9.1-4.el8_2.1.i686.rpm SHA-256: 72970800ddd3570c182b3d9a243739409d017413c487031ebb9097aaa8873abc
freetype-debugsource-2.9.1-4.el8_2.1.x86_64.rpm SHA-256: f953d1b4b6182543898e8c04c5688fe47ab172af3804b3d95974828fe9ce9107
freetype-demos-debuginfo-2.9.1-4.el8_2.1.i686.rpm SHA-256: 480f21152ffba45488439b989fb8cf0e70b997f656db11f92e339cafec9dfc64
freetype-demos-debuginfo-2.9.1-4.el8_2.1.x86_64.rpm SHA-256: 4080b2beeeb0e6274e59ce57d8ba25726f01a9c30e3aebd80cf95c7229c63d15
freetype-devel-2.9.1-4.el8_2.1.i686.rpm SHA-256: 0b43cfce0f9d7324a2a9936869beef3f131cfb809ec3e3c257301b4424ad0c0f
freetype-devel-2.9.1-4.el8_2.1.x86_64.rpm SHA-256: 9f1a90af056da580a04a8757995a05103aab755a3119d4ee35302efa04e53a7d

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.2

SRPM
freetype-2.9.1-4.el8_2.1.src.rpm SHA-256: 34de9c1c1147e0aa70260ca565bfd1e0e976dd97118c30dfe5c6587494df8d0b
s390x
freetype-2.9.1-4.el8_2.1.s390x.rpm SHA-256: 9171270dea86c5d47ab46c78bcdc0a92c29d853fc53dbfe6cc320bea81d0e4ad
freetype-debuginfo-2.9.1-4.el8_2.1.s390x.rpm SHA-256: 3b8eb0366df0c1a61a30cadc00dc7faacc727ed9f1026f3f4a49a39bcc7ac8f6
freetype-debugsource-2.9.1-4.el8_2.1.s390x.rpm SHA-256: 2aea508a1a5bf738ac2e4e3cae0906d8adb5ddb02347aceb1482548fc14de931
freetype-demos-debuginfo-2.9.1-4.el8_2.1.s390x.rpm SHA-256: ea2d0c683d0d43ea171a771bdc904130be20df466d4b5aa7e4e0b1809ecacc82
freetype-devel-2.9.1-4.el8_2.1.s390x.rpm SHA-256: 092fc4ee566e1aa76d52d6fb8235cd1ec1a3f3a5649a62f059aaf366d0350ec9

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.2

SRPM
freetype-2.9.1-4.el8_2.1.src.rpm SHA-256: 34de9c1c1147e0aa70260ca565bfd1e0e976dd97118c30dfe5c6587494df8d0b
ppc64le
freetype-2.9.1-4.el8_2.1.ppc64le.rpm SHA-256: 201c7e413e89b0b982b9bd95a7016dbff7b8170e4409d7f2d2da3406063cc770
freetype-debuginfo-2.9.1-4.el8_2.1.ppc64le.rpm SHA-256: cf5016d07c458392e924ab91d6c0ab9878acbad4d51ad592634b814dfaec6985
freetype-debugsource-2.9.1-4.el8_2.1.ppc64le.rpm SHA-256: f6645ba606e45d924a1743a4172fbfda1d198ddb4a196d74bff8704005892e05
freetype-demos-debuginfo-2.9.1-4.el8_2.1.ppc64le.rpm SHA-256: ab567b6334653a16907e936ffd693eb246467db8617874dc37cc8734cf432ab2
freetype-devel-2.9.1-4.el8_2.1.ppc64le.rpm SHA-256: c01e0ae2b649df9a63fa2ac7bd6e9b81835c35ddac272ee33d199f75298a8efb

Red Hat Enterprise Linux Server - TUS 8.2

SRPM
freetype-2.9.1-4.el8_2.1.src.rpm SHA-256: 34de9c1c1147e0aa70260ca565bfd1e0e976dd97118c30dfe5c6587494df8d0b
x86_64
freetype-2.9.1-4.el8_2.1.i686.rpm SHA-256: 38352545adbea288b0ae3201de4a61553d374b238e5303a8027bba56b8a49034
freetype-2.9.1-4.el8_2.1.x86_64.rpm SHA-256: 82a03989bcdbc0583300604f0c69cbe0386a3d4e80eb886ead3e77e6a3a4ebc1
freetype-debuginfo-2.9.1-4.el8_2.1.i686.rpm SHA-256: 8b8e3b0b3f8befde359d055c88506aa81302fe088d30a046e723a2264b709a00
freetype-debuginfo-2.9.1-4.el8_2.1.x86_64.rpm SHA-256: cd81e0ec198303b460198152979a2f48d97d19f5ab3d50186d8e87dcffdd63b6
freetype-debugsource-2.9.1-4.el8_2.1.i686.rpm SHA-256: 72970800ddd3570c182b3d9a243739409d017413c487031ebb9097aaa8873abc
freetype-debugsource-2.9.1-4.el8_2.1.x86_64.rpm SHA-256: f953d1b4b6182543898e8c04c5688fe47ab172af3804b3d95974828fe9ce9107
freetype-demos-debuginfo-2.9.1-4.el8_2.1.i686.rpm SHA-256: 480f21152ffba45488439b989fb8cf0e70b997f656db11f92e339cafec9dfc64
freetype-demos-debuginfo-2.9.1-4.el8_2.1.x86_64.rpm SHA-256: 4080b2beeeb0e6274e59ce57d8ba25726f01a9c30e3aebd80cf95c7229c63d15
freetype-devel-2.9.1-4.el8_2.1.i686.rpm SHA-256: 0b43cfce0f9d7324a2a9936869beef3f131cfb809ec3e3c257301b4424ad0c0f
freetype-devel-2.9.1-4.el8_2.1.x86_64.rpm SHA-256: 9f1a90af056da580a04a8757995a05103aab755a3119d4ee35302efa04e53a7d

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.2

SRPM
freetype-2.9.1-4.el8_2.1.src.rpm SHA-256: 34de9c1c1147e0aa70260ca565bfd1e0e976dd97118c30dfe5c6587494df8d0b
aarch64
freetype-2.9.1-4.el8_2.1.aarch64.rpm SHA-256: e521a9211003adbfbd7ce3ecc59a07e174dd1c0ecb10050bb379fcbca9e0927c
freetype-debuginfo-2.9.1-4.el8_2.1.aarch64.rpm SHA-256: 68bcd63ceee7cd579b065198b1b432ffdf99662d344ff184c10bac3f96fa429c
freetype-debugsource-2.9.1-4.el8_2.1.aarch64.rpm SHA-256: 5c9843c7501996b0b18b7b6cbe615bbb0eb66704520b23eb20171b6215de879a
freetype-demos-debuginfo-2.9.1-4.el8_2.1.aarch64.rpm SHA-256: e41711f882b4923d446c8ca8736bcc24d3d5bc87e9090355ba29b4d754261bf8
freetype-devel-2.9.1-4.el8_2.1.aarch64.rpm SHA-256: aecca2f6da46f51a8076b5a37e613b6a39b1e6d20737f85268b9116963a400a4

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.2

SRPM
freetype-2.9.1-4.el8_2.1.src.rpm SHA-256: 34de9c1c1147e0aa70260ca565bfd1e0e976dd97118c30dfe5c6587494df8d0b
ppc64le
freetype-2.9.1-4.el8_2.1.ppc64le.rpm SHA-256: 201c7e413e89b0b982b9bd95a7016dbff7b8170e4409d7f2d2da3406063cc770
freetype-debuginfo-2.9.1-4.el8_2.1.ppc64le.rpm SHA-256: cf5016d07c458392e924ab91d6c0ab9878acbad4d51ad592634b814dfaec6985
freetype-debugsource-2.9.1-4.el8_2.1.ppc64le.rpm SHA-256: f6645ba606e45d924a1743a4172fbfda1d198ddb4a196d74bff8704005892e05
freetype-demos-debuginfo-2.9.1-4.el8_2.1.ppc64le.rpm SHA-256: ab567b6334653a16907e936ffd693eb246467db8617874dc37cc8734cf432ab2
freetype-devel-2.9.1-4.el8_2.1.ppc64le.rpm SHA-256: c01e0ae2b649df9a63fa2ac7bd6e9b81835c35ddac272ee33d199f75298a8efb

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.2

SRPM
freetype-2.9.1-4.el8_2.1.src.rpm SHA-256: 34de9c1c1147e0aa70260ca565bfd1e0e976dd97118c30dfe5c6587494df8d0b
x86_64
freetype-2.9.1-4.el8_2.1.i686.rpm SHA-256: 38352545adbea288b0ae3201de4a61553d374b238e5303a8027bba56b8a49034
freetype-2.9.1-4.el8_2.1.x86_64.rpm SHA-256: 82a03989bcdbc0583300604f0c69cbe0386a3d4e80eb886ead3e77e6a3a4ebc1
freetype-debuginfo-2.9.1-4.el8_2.1.i686.rpm SHA-256: 8b8e3b0b3f8befde359d055c88506aa81302fe088d30a046e723a2264b709a00
freetype-debuginfo-2.9.1-4.el8_2.1.x86_64.rpm SHA-256: cd81e0ec198303b460198152979a2f48d97d19f5ab3d50186d8e87dcffdd63b6
freetype-debugsource-2.9.1-4.el8_2.1.i686.rpm SHA-256: 72970800ddd3570c182b3d9a243739409d017413c487031ebb9097aaa8873abc
freetype-debugsource-2.9.1-4.el8_2.1.x86_64.rpm SHA-256: f953d1b4b6182543898e8c04c5688fe47ab172af3804b3d95974828fe9ce9107
freetype-demos-debuginfo-2.9.1-4.el8_2.1.i686.rpm SHA-256: 480f21152ffba45488439b989fb8cf0e70b997f656db11f92e339cafec9dfc64
freetype-demos-debuginfo-2.9.1-4.el8_2.1.x86_64.rpm SHA-256: 4080b2beeeb0e6274e59ce57d8ba25726f01a9c30e3aebd80cf95c7229c63d15
freetype-devel-2.9.1-4.el8_2.1.i686.rpm SHA-256: 0b43cfce0f9d7324a2a9936869beef3f131cfb809ec3e3c257301b4424ad0c0f
freetype-devel-2.9.1-4.el8_2.1.x86_64.rpm SHA-256: 9f1a90af056da580a04a8757995a05103aab755a3119d4ee35302efa04e53a7d

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility