CVE-2014-9657
published 2015-02-08CVE-2014-9657: The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause…
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.06%
91.4th percentile
The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | freetype | < freetype 2.5.2-3 (bookworm) | freetype 2.5.2-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| freetype | freetype | <= 2.5.3 | — |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
| oracle | solaris | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p6rq-q7ph-2x7q: The tt_face_load_hdmx function in truetype/ttpload
ghsa_unreviewed·2022-05-14
CVE-2014-9657 [HIGH] CWE-125 GHSA-p6rq-q7ph-2x7q: The tt_face_load_hdmx function in truetype/ttpload
The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
OSV
CVE-2014-9657: The tt_face_load_hdmx function in truetype/ttpload
osv·2015-02-08·CVSS 7.5
CVE-2014-9657 [HIGH] CVE-2014-9657: The tt_face_load_hdmx function in truetype/ttpload
The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
Ubuntu
FreeType vulnerabilities
vendor_ubuntu·2015-02-24
CVE-2014-9656 FreeType vulnerabilities
Title: FreeType vulnerabilities
Summary: FreeType could be made to crash or run programs as your login if it opened
a specially crafted file.
Mateusz Jurczyk discovered that FreeType did not correctly handle certain
malformed font files. If a user were tricked into using a specially crafted
font file, a remote attacker could cause FreeType to crash or possibly
execute arbitrary code with user privileges.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Red Hat
freetype: off-by-one buffer over-read in tt_face_load_hdmx()
vendor_redhat·2014-11-24·CVSS 7.5
CVE-2014-9657 [HIGH] CWE-193 freetype: off-by-one buffer over-read in tt_face_load_hdmx()
freetype: off-by-one buffer over-read in tt_face_load_hdmx()
The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
Package: freetype (Red Hat Enterprise Linux 4) - Will not fix
Package: freetype (Red Hat Enterprise Linux 5) - Will not fix
Package: mingw-virt-viewer (Red Hat Enterprise Virtualization 3) - Affected
Debian
CVE-2014-9657: freetype - The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 do...
vendor_debian·2014·CVSS 7.5
CVE-2014-9657 [HIGH] CVE-2014-9657: freetype - The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 do...
The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
Scope: local
bookworm: resolved (fixed in 2.5.2-3)
bullseye: resolved (fixed in 2.5.2-3)
forky: resolved (fixed in 2.5.2-3)
sid: resolved (fixed in 2.5.2-3)
trixie: resolved (fixed in 2.5.2-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9656 CVE-2014-9657 CVE-2014-9661 CVE-2014-9660 CVE-2014-9667 CVE-2014-9666 CVE-2014-9665 CVE-2014-9664 CVE-2014-9669 CVE-2014-9668 CVE-2014-9662 CVE-2014-9658 CVE-2014-9659 CVE-2014-9663 CVE-
bugzilla·2015-02-10·CVSS 7.5
CVE-2014-9656 [HIGH] CVE-2014-9656 CVE-2014-9657 CVE-2014-9661 CVE-2014-9660 CVE-2014-9667 CVE-2014-9666 CVE-2014-9665 CVE-2014-9664 CVE-2014-9669 CVE-2014-9668 CVE-2014-9662 CVE-2014-9658 CVE-2014-9659 CVE-2014-9663 CVE-
CVE-2014-9656 CVE-2014-9657 CVE-2014-9661 CVE-2014-9660 CVE-2014-9667 CVE-2014-9666 CVE-2014-9665 CVE-2014-9664 CVE-2014-9669 CVE-2014-9668 CVE-2014-9662 CVE-2014-9658 CVE-2014-9659 CVE-2014-9663 CVE-2014-9670 freetype: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-l
Bugzilla
CVE-2014-9657 freetype: off-by-one buffer over-read in tt_face_load_hdmx()
bugzilla·2015-02-10·CVSS 7.5
CVE-2014-9657 [HIGH] CVE-2014-9657 freetype: off-by-one buffer over-read in tt_face_load_hdmx()
CVE-2014-9657 freetype: off-by-one buffer over-read in tt_face_load_hdmx()
Common Vulnerabilities and Exposures assigned CVE-2014-9657 to the following issue:
The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4
does not establish a minimum record size, which allows remote attackers to cause
a denial of service (out-of-bounds read) or possibly have unspecified other
impact via a crafted TrueType font.
http://code.google.com/p/google-security-research/issues/detail?id=195
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=eca0f067068020870a429fe91f6329e499390d55
Discussion:
Created freetype tracking bugs for this issue:
Affects: fedora-all [bug 1191099]
---
Upstream bug is:
https://savannah.nongnu.org/bugs/?43679
Issue was fixed upstream in
http://advisories.mageia.org/MGASA-2015-0083.htmlhttp://code.google.com/p/google-security-research/issues/detail?id=195http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=eca0f067068020870a429fe91f6329e499390d55http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150148.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-February/150162.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00091.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0696.htmlhttp://www.debian.org/security/2015/dsa-3188http://www.mandriva.com/security/advisories?name=MDVSA-2015:055http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/72986http://www.ubuntu.com/usn/USN-2510-1http://www.ubuntu.com/usn/USN-2739-1https://security.gentoo.org/glsa/201503-05http://advisories.mageia.org/MGASA-2015-0083.htmlhttp://code.google.com/p/google-security-research/issues/detail?id=195http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=eca0f067068020870a429fe91f6329e499390d55http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150148.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-February/150162.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00091.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0696.htmlhttp://www.debian.org/security/2015/dsa-3188http://www.mandriva.com/security/advisories?name=MDVSA-2015:055http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/72986http://www.ubuntu.com/usn/USN-2510-1http://www.ubuntu.com/usn/USN-2739-1https://security.gentoo.org/glsa/201503-05
2015-02-08
Published