CVE-2014-9667
published 2015-02-08CVE-2014-9667: sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to cause a denial…
PriorityP428medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.49%
87.8th percentile
sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted SFNT table.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | freetype | < freetype 2.5.2-3 (bookworm) | freetype 2.5.2-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| freetype | freetype | <= 2.5.3 | — |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xpf7-vf54-5crr: sfnt/ttload
ghsa_unreviewed·2022-05-14
CVE-2014-9667 [MEDIUM] CWE-119 GHSA-xpf7-vf54-5crr: sfnt/ttload
sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted SFNT table.
OSV
CVE-2014-9667: sfnt/ttload
osv·2015-02-08·CVSS 6.8
CVE-2014-9667 [MEDIUM] CVE-2014-9667: sfnt/ttload
sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted SFNT table.
Ubuntu
FreeType vulnerabilities
vendor_ubuntu·2015-02-24
CVE-2014-9656 FreeType vulnerabilities
Title: FreeType vulnerabilities
Summary: FreeType could be made to crash or run programs as your login if it opened
a specially crafted file.
Mateusz Jurczyk discovered that FreeType did not correctly handle certain
malformed font files. If a user were tricked into using a specially crafted
font file, a remote attacker could cause FreeType to crash or possibly
execute arbitrary code with user privileges.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Red Hat
freetype: integer overflow in tt_face_load_font_dir() leading to out-of-bounds read
vendor_redhat·2014-11-24·CVSS 6.8
CVE-2014-9667 [MEDIUM] CWE-190 freetype: integer overflow in tt_face_load_font_dir() leading to out-of-bounds read
freetype: integer overflow in tt_face_load_font_dir() leading to out-of-bounds read
sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted SFNT table.
Package: freetype (Red Hat Enterprise Linux 4) - Will not fix
Package: freetype (Red Hat Enterprise Linux 5) - Will not fix
Package: mingw-virt-viewer (Red Hat Enterprise Virtualization 3) - Affected
Debian
CVE-2014-9667: freetype - sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations ...
vendor_debian·2014·CVSS 6.8
CVE-2014-9667 [MEDIUM] CVE-2014-9667: freetype - sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations ...
sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted SFNT table.
Scope: local
bookworm: resolved (fixed in 2.5.2-3)
bullseye: resolved (fixed in 2.5.2-3)
forky: resolved (fixed in 2.5.2-3)
sid: resolved (fixed in 2.5.2-3)
trixie: resolved (fixed in 2.5.2-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9656 CVE-2014-9657 CVE-2014-9661 CVE-2014-9660 CVE-2014-9667 CVE-2014-9666 CVE-2014-9665 CVE-2014-9664 CVE-2014-9669 CVE-2014-9668 CVE-2014-9662 CVE-2014-9658 CVE-2014-9659 CVE-2014-9663 CVE-
bugzilla·2015-02-10·CVSS 7.5
CVE-2014-9656 [HIGH] CVE-2014-9656 CVE-2014-9657 CVE-2014-9661 CVE-2014-9660 CVE-2014-9667 CVE-2014-9666 CVE-2014-9665 CVE-2014-9664 CVE-2014-9669 CVE-2014-9668 CVE-2014-9662 CVE-2014-9658 CVE-2014-9659 CVE-2014-9663 CVE-
CVE-2014-9656 CVE-2014-9657 CVE-2014-9661 CVE-2014-9660 CVE-2014-9667 CVE-2014-9666 CVE-2014-9665 CVE-2014-9664 CVE-2014-9669 CVE-2014-9668 CVE-2014-9662 CVE-2014-9658 CVE-2014-9659 CVE-2014-9663 CVE-2014-9670 freetype: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-l
Bugzilla
CVE-2014-9667 freetype: integer overflow in tt_face_load_font_dir() leading to out-of-bounds read
bugzilla·2015-02-10·CVSS 6.8
CVE-2014-9667 [MEDIUM] CVE-2014-9667 freetype: integer overflow in tt_face_load_font_dir() leading to out-of-bounds read
CVE-2014-9667 freetype: integer overflow in tt_face_load_font_dir() leading to out-of-bounds read
Common Vulnerabilities and Exposures assigned CVE-2014-9667 to the following issue:
sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations
without restricting the values, which allows remote attackers to cause a denial
of service (integer overflow and out-of-bounds read) or possibly have
unspecified other impact via a crafted SFNT table.
http://code.google.com/p/google-security-research/issues/detail?id=166
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=677ddf4f1dc1b36cef7c7ddd59a14c508f4b1891
Discussion:
Created freetype tracking bugs for this issue:
Affects: fedora-all [bug 1191099]
---
freetype-2.5.3-15.fc21 has been pushed to the Fedora
http://advisories.mageia.org/MGASA-2015-0083.htmlhttp://code.google.com/p/google-security-research/issues/detail?id=166http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=677ddf4f1dc1b36cef7c7ddd59a14c508f4b1891http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150148.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-February/150162.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00091.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0696.htmlhttp://www.debian.org/security/2015/dsa-3188http://www.mandriva.com/security/advisories?name=MDVSA-2015:055http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/72986http://www.ubuntu.com/usn/USN-2510-1http://www.ubuntu.com/usn/USN-2739-1https://security.gentoo.org/glsa/201503-05http://advisories.mageia.org/MGASA-2015-0083.htmlhttp://code.google.com/p/google-security-research/issues/detail?id=166http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=677ddf4f1dc1b36cef7c7ddd59a14c508f4b1891http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150148.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-February/150162.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00091.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0696.htmlhttp://www.debian.org/security/2015/dsa-3188http://www.mandriva.com/security/advisories?name=MDVSA-2015:055http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/72986http://www.ubuntu.com/usn/USN-2510-1http://www.ubuntu.com/usn/USN-2739-1https://security.gentoo.org/glsa/201503-05
2015-02-08
Published