CVE-2014-9664
published 2015-02-08CVE-2014-9664: FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service…
PriorityP430medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.27%
90.0th percentile
FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted Type42 font, related to type42/t42parse.c and type1/t1load.c.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | freetype | < freetype 2.5.2-3 (bookworm) | freetype 2.5.2-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| freetype | freetype | <= 2.5.3 | — |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
| oracle | solaris | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-96vp-w36f-3m77: FreeType before 2
ghsa_unreviewed·2022-05-14
CVE-2014-9664 [MEDIUM] CWE-119 GHSA-96vp-w36f-3m77: FreeType before 2
FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted Type42 font, related to type42/t42parse.c and type1/t1load.c.
OSV
CVE-2014-9664: FreeType before 2
osv·2015-02-08·CVSS 6.8
CVE-2014-9664 [MEDIUM] CVE-2014-9664: FreeType before 2
FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted Type42 font, related to type42/t42parse.c and type1/t1load.c.
Ubuntu
FreeType vulnerabilities
vendor_ubuntu·2015-02-24
CVE-2014-9656 FreeType vulnerabilities
Title: FreeType vulnerabilities
Summary: FreeType could be made to crash or run programs as your login if it opened
a specially crafted file.
Mateusz Jurczyk discovered that FreeType did not correctly handle certain
malformed font files. If a user were tricked into using a specially crafted
font file, a remote attacker could cause FreeType to crash or possibly
execute arbitrary code with user privileges.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Red Hat
freetype: off-by-one buffer over-read in parse_charstrings() / t42_parse_charstrings()
vendor_redhat·2014-11-24·CVSS 6.8
CVE-2014-9664 [MEDIUM] CWE-193 freetype: off-by-one buffer over-read in parse_charstrings() / t42_parse_charstrings()
freetype: off-by-one buffer over-read in parse_charstrings() / t42_parse_charstrings()
FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted Type42 font, related to type42/t42parse.c and type1/t1load.c.
Package: freetype (Red Hat Enterprise Linux 4) - Will not fix
Package: freetype (Red Hat Enterprise Linux 5) - Will not fix
Package: mingw-virt-viewer (Red Hat Enterprise Virtualization 3) - Affected
Debian
CVE-2014-9664: freetype - FreeType before 2.5.4 does not check for the end of the data during certain pars...
vendor_debian·2014·CVSS 6.8
CVE-2014-9664 [MEDIUM] CVE-2014-9664: freetype - FreeType before 2.5.4 does not check for the end of the data during certain pars...
FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted Type42 font, related to type42/t42parse.c and type1/t1load.c.
Scope: local
bookworm: resolved (fixed in 2.5.2-3)
bullseye: resolved (fixed in 2.5.2-3)
forky: resolved (fixed in 2.5.2-3)
sid: resolved (fixed in 2.5.2-3)
trixie: resolved (fixed in 2.5.2-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9656 CVE-2014-9657 CVE-2014-9661 CVE-2014-9660 CVE-2014-9667 CVE-2014-9666 CVE-2014-9665 CVE-2014-9664 CVE-2014-9669 CVE-2014-9668 CVE-2014-9662 CVE-2014-9658 CVE-2014-9659 CVE-2014-9663 CVE-
bugzilla·2015-02-10·CVSS 7.5
CVE-2014-9656 [HIGH] CVE-2014-9656 CVE-2014-9657 CVE-2014-9661 CVE-2014-9660 CVE-2014-9667 CVE-2014-9666 CVE-2014-9665 CVE-2014-9664 CVE-2014-9669 CVE-2014-9668 CVE-2014-9662 CVE-2014-9658 CVE-2014-9659 CVE-2014-9663 CVE-
CVE-2014-9656 CVE-2014-9657 CVE-2014-9661 CVE-2014-9660 CVE-2014-9667 CVE-2014-9666 CVE-2014-9665 CVE-2014-9664 CVE-2014-9669 CVE-2014-9668 CVE-2014-9662 CVE-2014-9658 CVE-2014-9659 CVE-2014-9663 CVE-2014-9670 freetype: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-l
Bugzilla
CVE-2014-9664 freetype: off-by-one buffer over-read in parse_charstrings() / t42_parse_charstrings()
bugzilla·2015-02-10·CVSS 6.8
CVE-2014-9664 [MEDIUM] CVE-2014-9664 freetype: off-by-one buffer over-read in parse_charstrings() / t42_parse_charstrings()
CVE-2014-9664 freetype: off-by-one buffer over-read in parse_charstrings() / t42_parse_charstrings()
Common Vulnerabilities and Exposures assigned CVE-2014-9664 to the following issue:
FreeType before 2.5.4 does not check for the end of the data during certain
parsing actions, which allows remote attackers to cause a denial of service
(out-of-bounds read) or possibly have unspecified other impact via a crafted
Type42 font, related to type42/t42parse.c and type1/t1load.c.
http://code.google.com/p/google-security-research/issues/detail?id=183
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=73be9f9ab67842cfbec36ee99e8d2301434c84ca
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=dd89710f0f643eb0f99a3830e0712d26c7642acd
Discussion:
Created freetype tra
arXiv
On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities
arxiv_fulltext·2024-01-20
On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities
On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities
Zhen Li
National Engineering Research Center for Big Data Technology and System, Services Computing Technology and System Lab, Hubei Key Laboratory of Distributed System Security, Hubei Engineering Research Center on Big Data Security, Cluster and Grid Computing Lab
JinYinHu Laboratory, Wuhan, China
School of Cyber Science and Engineering, Huazhong University of Science and Technology
Wuhan
China
[email protected]
Ning Wang
[1]
School of Cyber Science and Engineering, Huazhong University of Science and Technology
Wuhan
China
[email protected]
Deqing Zou
[1]
[2]
Corresponding author
School of Cyber Science and Engineering, Huazhong University of Science and Technology
Wuhan
China
d
http://advisories.mageia.org/MGASA-2015-0083.htmlhttp://code.google.com/p/google-security-research/issues/detail?id=183http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=73be9f9ab67842cfbec36ee99e8d2301434c84cahttp://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=dd89710f0f643eb0f99a3830e0712d26c7642acdhttp://lists.fedoraproject.org/pipermail/package-announce/2015-February/150148.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-February/150162.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00091.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0696.htmlhttp://www.debian.org/security/2015/dsa-3188http://www.mandriva.com/security/advisories?name=MDVSA-2015:055http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/72986http://www.ubuntu.com/usn/USN-2510-1http://www.ubuntu.com/usn/USN-2739-1https://security.gentoo.org/glsa/201503-05http://advisories.mageia.org/MGASA-2015-0083.htmlhttp://code.google.com/p/google-security-research/issues/detail?id=183http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=73be9f9ab67842cfbec36ee99e8d2301434c84cahttp://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=dd89710f0f643eb0f99a3830e0712d26c7642acdhttp://lists.fedoraproject.org/pipermail/package-announce/2015-February/150148.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-February/150162.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00091.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0696.htmlhttp://www.debian.org/security/2015/dsa-3188http://www.mandriva.com/security/advisories?name=MDVSA-2015:055http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/72986http://www.ubuntu.com/usn/USN-2510-1http://www.ubuntu.com/usn/USN-2739-1https://security.gentoo.org/glsa/201503-05
2015-02-08
Published