CVE-2014-2241
published 2014-03-18CVE-2014-2241: The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a subroutine…
PriorityP425medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.57%
72.6th percentile
The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a subroutine exists, which allows remote attackers to cause a denial of service (assertion failure), as demonstrated by a crafted ttf file.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | freetype | < freetype 2.5.2-1.1 (bookworm) | freetype 2.5.2-1.1 (bookworm) |
| freetype | freetype | <= 2.5.2 | — |
| freetype | freetype | — | — |
| freetype | freetype | — | — |
| freetype | freetype | >= 0 < 2.5.2-1.1 | 2.5.2-1.1 |
| freetype | freetype | >= 0 < 2.5.2-1.1 | 2.5.2-1.1 |
| freetype | freetype | >= 0 < 2.5.2-1.1 | 2.5.2-1.1 |
| freetype | freetype | >= 0 < 2.5.2-1.1 | 2.5.2-1.1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FreeType vulnerabilities
vendor_ubuntu·2014-03-17·CVSS 7.5
CVE-2014-2240 [HIGH] FreeType vulnerabilities
Title: FreeType vulnerabilities
Summary: FreeType could be made to crash or run programs as your login if it opened
a specially crafted font file.
Mateusz Jurczyk discovered that FreeType did not correctly handle certain
malformed font files. If a user were tricked into using a specially crafted
font file, a remote attacker could cause FreeType to crash or possibly
execute arbitrary code with user privileges. (CVE-2014-2240, CVE-2014-2241)
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
freetype: OOB stack-based read/write in cf2_hintmap_build()
vendor_redhat·2014-03-07·CVSS 6.8
CVE-2014-2241 [MEDIUM] CWE-121 freetype: OOB stack-based read/write in cf2_hintmap_build()
freetype: OOB stack-based read/write in cf2_hintmap_build()
The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a subroutine exists, which allows remote attackers to cause a denial of service (assertion failure), as demonstrated by a crafted ttf file.
Statement: Not vulnerable. This issue did not affect the versions of freetype as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: freetype (Red Hat Enterprise Linux 5) - Not affected
Package: freetype (Red Hat Enterprise Linux 6) - Not affected
Package: freetype (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2014-2241: freetype - The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions i...
vendor_debian·2014·CVSS 6.8
CVE-2014-2241 [MEDIUM] CVE-2014-2241: freetype - The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions i...
The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a subroutine exists, which allows remote attackers to cause a denial of service (assertion failure), as demonstrated by a crafted ttf file.
Scope: local
bookworm: resolved (fixed in 2.5.2-1.1)
bullseye: resolved (fixed in 2.5.2-1.1)
forky: resolved (fixed in 2.5.2-1.1)
sid: resolved (fixed in 2.5.2-1.1)
trixie: resolved (fixed in 2.5.2-1.1)
GHSA
GHSA-39qr-hvc6-f2x3: The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft
ghsa_unreviewed·2022-05-17
CVE-2014-2241 [MEDIUM] CWE-20 GHSA-39qr-hvc6-f2x3: The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft
The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a subroutine exists, which allows remote attackers to cause a denial of service (assertion failure), as demonstrated by a crafted ttf file.
OSV
CVE-2014-2241: The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft
osv·2014-03-18·CVSS 6.8
CVE-2014-2241 [MEDIUM] CVE-2014-2241: The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft
The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a subroutine exists, which allows remote attackers to cause a denial of service (assertion failure), as demonstrated by a crafted ttf file.
No detection rules found.
No public exploits indexed.
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=135c3faebb96f8f550bd4f318716f2e1e095a969http://savannah.nongnu.org/bugs/?41697http://secunia.com/advisories/57447http://www.openwall.com/lists/oss-security/2014/03/12/4http://www.ubuntu.com/usn/USN-2148-1http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=135c3faebb96f8f550bd4f318716f2e1e095a969http://savannah.nongnu.org/bugs/?41697http://secunia.com/advisories/57447http://www.openwall.com/lists/oss-security/2014/03/12/4http://www.ubuntu.com/usn/USN-2148-1
2014-03-18
Published