Property Value
Distribution Ubuntu 16.04 LTS (Xenial Xerus)
Repository Ubuntu Main amd64
Package filename libxfont1_1.5.1-1_amd64.deb
Package name libxfont1
Package version 1.5.1
Package release 1
Package architecture amd64
Package type deb
Category libs
Homepage -
License -
Maintainer Ubuntu Developers <>
Download size 92.50 KB
Installed size 241.00 KB
libXfont provides various services for X servers, most notably font
selection and rasterisation (through external libraries).
More information about X.Org can be found at:
This module can be found at


Package Version Architecture Repository
libxfont1_1.5.1-1ubuntu0.16.04.4_i386.deb 1.5.1 i386 Ubuntu Updates Main
libxfont1_1.5.1-1ubuntu0.16.04.4_amd64.deb 1.5.1 amd64 Ubuntu Updates Main
libxfont1_1.5.1-1_i386.deb 1.5.1 i386 Ubuntu Main
libxfont1 - - -


Name Value
libbz2-1.0 -
libc6 >= 2.14
libfontenc1 -
libfreetype6 >= 2.2.1
multiarch-support -
zlib1g >= 1:1.1.4


Name Value
xprint << 2:1.6.0-1


Type URL
Binary Package libxfont1_1.5.1-1_amd64.deb
Source Package libxfont

2015-03-17 - Julien Cristau <>
libxfont (1:1.5.1-1) unstable; urgency=high
* New upstream release
+ bdfReadProperties: property count needs range check [CVE-2015-1802]
+ bdfReadCharacters: bailout if a char's bitmap cannot be read
+ bdfReadCharacters: ensure metrics fit into xCharInfo struct
2014-07-12 - Julien Cristau <>
libxfont (1: unstable; urgency=medium
* New upstream release candidate.
+ includes the CVE-2014-{0209,0210,0211} patches
* Remove Cyril from Uploaders.
* Allow uscan to verify tarball signature.
2014-05-13 - Julien Cristau <>
libxfont (1:1.4.7-2) unstable; urgency=high
* Pull from upstream git to fix FTBFS with new fontsproto (closes: #746052)
* CVE-2014-0209: integer overflow of allocations in font metadata
* CVE-2014-0210: unvalidated length fields when parsing xfs protocol replies
* CVE-2014-0211: integer overflows calculating memory needs for xfs replies
* Add breaks on xfs because we broke it by disabling font protocol support
in 1.4.7.
2014-01-07 - Julien Cristau <>
libxfont (1:1.4.7-1) unstable; urgency=high
* New upstream release
+ CVE-2013-6462: unlimited sscanf overflows stack buffer in
* Don't put dbg symbols from the udeb in the dbg package.
* dev package is no longer Multi-Arch: same (closes: #720026).
* Disable support for connecting to a font server.  That code is horrible and
full of holes.
2013-08-12 - Julien Cristau <>
libxfont (1:1.4.6-1) unstable; urgency=low
* New upstream release.
* Build for multiarch (closes: #654252).  Patch by Riku Voipio, thanks!
* Disable silent build rules.
2012-05-03 - Cyril Brulebois <>
libxfont (1:1.4.5-2) unstable; urgency=low
* Ease sync for Ubuntu: strip -Bsymbolic-functions from LDFLAGS
(LP: #992745).
2012-03-04 - Cyril Brulebois <>
libxfont (1:1.4.5-1) unstable; urgency=low
[ Cyril Brulebois ]
* New upstream release.
* Switch to dh:
- Bump debhelper build-dep and compat.
- Rewrite debian/rules, using autoreconf and quilt sequences.
- Adjust build dependencies accordingly.
- Use build-main and build-udeb as build directories.
- Adjust .install accordingly.
* Remove xsfbs accordingly.
* Add support for hardened build flags through dpkg-buildflags, based
on a patch by Moritz Muehlenhoff, thanks! (Closes: #654154).
[ Julien Cristau ]
* Remove David Nusinow from Uploaders.
2011-08-11 - Cyril Brulebois <>
libxfont (1:1.4.4-1) unstable; urgency=high
[ Julien Cristau ]
* Drop Pre-Depends on x11-common (only needed for upgrades from the
monolith) and Replaces on xlibs-static-dev (hasn't existed in forever).
[ Cyril Brulebois ]
* New upstream release:
- LZW decompress: fix for CVE-2011-2895. From the commit message:
“Specially crafted LZW stream can crash an application using libXfont
that is used to open untrusted font files.  With X server, this may
allow privilege escalation when exploited.”
* Set urgency to “high” accordingly.
* Update debian/copyright from upstream COPYING.
* Bump xorg-sgml-doctools build-dep.
* Drop xorg.css from .install, no longer shipped upstream.
2011-02-05 - Cyril Brulebois <>
libxfont (1:1.4.3-2) unstable; urgency=low
* Upload to unstable.
2010-11-19 - Cyril Brulebois <>
libxfont (1:1.4.3-1) experimental; urgency=low
* New upstream release.
* Bump xutils-dev build-dep for new macros.
* Add xmlto, xorg-sgml-doctools, and w3m build-dep for the doc.
* Pass --with-xmlto and --without-fop for the regular build (we want
html and txt only). Disable both for the udeb build.
* Tweak doc filenames, and handle that through dh_install.
* Add --fail-missing for the second dh_install call (the
udeb one), for additional safety.

