CVE-2014-9658
published 2015-02-08CVE-2014-9658: The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, which allows remote attackers to cause a…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.06%
91.4th percentile
The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | freetype | < freetype 2.5.2-3 (bookworm) | freetype 2.5.2-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| freetype | freetype | <= 2.5.3 | — |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
| oracle | solaris | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FreeType vulnerabilities
vendor_ubuntu·2015-02-24
CVE-2014-9656 FreeType vulnerabilities
Title: FreeType vulnerabilities
Summary: FreeType could be made to crash or run programs as your login if it opened
a specially crafted file.
Mateusz Jurczyk discovered that FreeType did not correctly handle certain
malformed font files. If a user were tricked into using a specially crafted
font file, a remote attacker could cause FreeType to crash or possibly
execute arbitrary code with user privileges.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Red Hat
freetype: buffer over-read and integer underflow in tt_face_load_kern()
vendor_redhat·2014-11-24·CVSS 7.5
CVE-2014-9658 [HIGH] CWE-20 freetype: buffer over-read and integer underflow in tt_face_load_kern()
freetype: buffer over-read and integer underflow in tt_face_load_kern()
The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
Package: freetype (Red Hat Enterprise Linux 4) - Not affected
Package: freetype (Red Hat Enterprise Linux 5) - Will not fix
Package: mingw-virt-viewer (Red Hat Enterprise Virtualization 3) - Affected
Debian
CVE-2014-9658: freetype - The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforce...
vendor_debian·2014·CVSS 7.5
CVE-2014-9658 [HIGH] CVE-2014-9658: freetype - The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforce...
The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
Scope: local
bookworm: resolved (fixed in 2.5.2-3)
bullseye: resolved (fixed in 2.5.2-3)
forky: resolved (fixed in 2.5.2-3)
sid: resolved (fixed in 2.5.2-3)
trixie: resolved (fixed in 2.5.2-3)
GHSA
GHSA-gmr3-ccjr-wqv8: The tt_face_load_kern function in sfnt/ttkern
ghsa_unreviewed·2022-05-14
CVE-2014-9658 [HIGH] CWE-125 GHSA-gmr3-ccjr-wqv8: The tt_face_load_kern function in sfnt/ttkern
The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
OSV
CVE-2014-9658: The tt_face_load_kern function in sfnt/ttkern
osv·2015-02-08·CVSS 7.5
CVE-2014-9658 [HIGH] CVE-2014-9658: The tt_face_load_kern function in sfnt/ttkern
The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9656 CVE-2014-9657 CVE-2014-9661 CVE-2014-9660 CVE-2014-9667 CVE-2014-9666 CVE-2014-9665 CVE-2014-9664 CVE-2014-9669 CVE-2014-9668 CVE-2014-9662 CVE-2014-9658 CVE-2014-9659 CVE-2014-9663 CVE-
bugzilla·2015-02-10·CVSS 7.5
CVE-2014-9656 [HIGH] CVE-2014-9656 CVE-2014-9657 CVE-2014-9661 CVE-2014-9660 CVE-2014-9667 CVE-2014-9666 CVE-2014-9665 CVE-2014-9664 CVE-2014-9669 CVE-2014-9668 CVE-2014-9662 CVE-2014-9658 CVE-2014-9659 CVE-2014-9663 CVE-
CVE-2014-9656 CVE-2014-9657 CVE-2014-9661 CVE-2014-9660 CVE-2014-9667 CVE-2014-9666 CVE-2014-9665 CVE-2014-9664 CVE-2014-9669 CVE-2014-9668 CVE-2014-9662 CVE-2014-9658 CVE-2014-9659 CVE-2014-9663 CVE-2014-9670 freetype: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-l
Bugzilla
CVE-2014-9658 freetype: buffer over-read and integer underflow in tt_face_load_kern()
bugzilla·2015-02-10·CVSS 7.5
CVE-2014-9658 [HIGH] CVE-2014-9658 freetype: buffer over-read and integer underflow in tt_face_load_kern()
CVE-2014-9658 freetype: buffer over-read and integer underflow in tt_face_load_kern()
Common Vulnerabilities and Exposures assigned CVE-2014-9658 to the following issue:
The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4
enforces an incorrect minimum table length, which allows remote attackers to
cause a denial of service (out-of-bounds read) or possibly have unspecified
other impact via a crafted TrueType font.
http://code.google.com/p/google-security-research/issues/detail?id=194
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=f70d9342e65cd2cb44e9f26b6d7edeedf191fc6c
Discussion:
Created freetype tracking bugs for this issue:
Affects: fedora-all [bug 1191099]
---
freetype-2.5.3-15.fc21 has been pushed to the Fedora 21 stable repository. If
http://advisories.mageia.org/MGASA-2015-0083.htmlhttp://code.google.com/p/google-security-research/issues/detail?id=194http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=f70d9342e65cd2cb44e9f26b6d7edeedf191fc6chttp://lists.fedoraproject.org/pipermail/package-announce/2015-February/150148.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-February/150162.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00091.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0696.htmlhttp://www.debian.org/security/2015/dsa-3188http://www.mandriva.com/security/advisories?name=MDVSA-2015:055http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/72986http://www.ubuntu.com/usn/USN-2510-1http://www.ubuntu.com/usn/USN-2739-1https://security.gentoo.org/glsa/201503-05http://advisories.mageia.org/MGASA-2015-0083.htmlhttp://code.google.com/p/google-security-research/issues/detail?id=194http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=f70d9342e65cd2cb44e9f26b6d7edeedf191fc6chttp://lists.fedoraproject.org/pipermail/package-announce/2015-February/150148.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-February/150162.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00091.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0696.htmlhttp://www.debian.org/security/2015/dsa-3188http://www.mandriva.com/security/advisories?name=MDVSA-2015:055http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/72986http://www.ubuntu.com/usn/USN-2510-1http://www.ubuntu.com/usn/USN-2739-1https://security.gentoo.org/glsa/201503-05
2015-02-08
Published