CVE-2014-9672
published 2015-02-08CVE-2014-9672: Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bounds read)…
PriorityP426medium5.8CVSS 2.0
AVNACMAuNCPINAP
EPSS
4.68%
90.8th percentile
Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information from process memory via a crafted FOND resource in a Mac font file.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | freetype | < freetype 2.5.2-3 (bookworm) | freetype 2.5.2-3 (bookworm) |
| freetype | freetype | <= 2.5.3 | — |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
| oracle | solaris | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-58fh-qf9x-f6j9: Array index error in the parse_fond function in base/ftmac
ghsa_unreviewed·2022-05-14
CVE-2014-9672 [MEDIUM] CWE-119 GHSA-58fh-qf9x-f6j9: Array index error in the parse_fond function in base/ftmac
Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information from process memory via a crafted FOND resource in a Mac font file.
OSV
CVE-2014-9672: Array index error in the parse_fond function in base/ftmac
osv·2015-02-08·CVSS 5.8
CVE-2014-9672 [MEDIUM] CVE-2014-9672: Array index error in the parse_fond function in base/ftmac
Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information from process memory via a crafted FOND resource in a Mac font file.
Ubuntu
FreeType vulnerabilities
vendor_ubuntu·2015-02-24
CVE-2014-9656 FreeType vulnerabilities
Title: FreeType vulnerabilities
Summary: FreeType could be made to crash or run programs as your login if it opened
a specially crafted file.
Mateusz Jurczyk discovered that FreeType did not correctly handle certain
malformed font files. If a user were tricked into using a specially crafted
font file, a remote attacker could cause FreeType to crash or possibly
execute arbitrary code with user privileges.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Red Hat
freetype: Array index error in the parse_fond function in base/ftmac.c
vendor_redhat·2014-11-24·CVSS 5.8
CVE-2014-9672 [MEDIUM] CWE-129 freetype: Array index error in the parse_fond function in base/ftmac.c
freetype: Array index error in the parse_fond function in base/ftmac.c
Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information from process memory via a crafted FOND resource in a Mac font file.
Statement: Not vulnerable. This issue did not affect the versions of freetype as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: freetype (Red Hat Enterprise Linux 4) - Not affected
Package: freetype (Red Hat Enterprise Linux 5) - Not affected
Package: freetype (Red Hat Enterprise Linux 6) - Not affected
Package: freetype (Red Hat Enterprise Linux 7) - Not affected
Package: mingw-virt-viewer (Red Hat Enterprise Virtualization 3) - Not affected
Debian
CVE-2014-9672: freetype - Array index error in the parse_fond function in base/ftmac.c in FreeType before ...
vendor_debian·2014·CVSS 5.8
CVE-2014-9672 [MEDIUM] CVE-2014-9672: freetype - Array index error in the parse_fond function in base/ftmac.c in FreeType before ...
Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information from process memory via a crafted FOND resource in a Mac font file.
Scope: local
bookworm: resolved (fixed in 2.5.2-3)
bullseye: resolved (fixed in 2.5.2-3)
forky: resolved (fixed in 2.5.2-3)
sid: resolved (fixed in 2.5.2-3)
trixie: resolved (fixed in 2.5.2-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9672 freetype: Array index error in the parse_fond function in base/ftmac.c
bugzilla·2015-02-10·CVSS 5.8
CVE-2014-9672 [MEDIUM] CVE-2014-9672 freetype: Array index error in the parse_fond function in base/ftmac.c
CVE-2014-9672 freetype: Array index error in the parse_fond function in base/ftmac.c
Common Vulnerabilities and Exposures assigned CVE-2014-9672 to the following issue:
Array index error in the parse_fond function in base/ftmac.c in FreeType before
2.5.4 allows remote attackers to cause a denial of service (out-of-bounds read)
or obtain sensitive information from process memory via a crafted FOND resource
in a Mac font file.
http://code.google.com/p/google-security-research/issues/detail?id=155
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=18a8f0d9943369449bc4de92d411c78fb08d616c
Discussion:
Upstream bug is:
https://savannah.nongnu.org/bugs/?43540
It remains non-public to date.
Issue was fixed upstream in 2.5.4.
Affected code is not built and used in freetype p
Bugzilla
CVE-2014-2281 wireshark: NFS dissector crash (wnpa-sec-2014-01)
bugzilla·2014-03-08·CVSS 4.3
CVE-2014-2281 [MEDIUM] CVE-2014-2281 wireshark: NFS dissector crash (wnpa-sec-2014-01)
CVE-2014-2281 wireshark: NFS dissector crash (wnpa-sec-2014-01)
It was reported that Wireshark's NFS dissector could crash. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
This is reported to affect Wireshark versions 1.10.0 to 1.10.5 and 1.8.0 to 1.8.12. It is fixed in 1.10.6 and 1.8.13.
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9672
External References:
http://www.wireshark.org/security/wnpa-sec-2014-01.html
Discussion:
Created wireshark tracking bugs for this issue:
Affects: fedora-all [bug 1074118]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2014:0342 https://rhn.redhat.com/errata/RHSA-2014-0342.html
---
This
http://advisories.mageia.org/MGASA-2015-0083.htmlhttp://code.google.com/p/google-security-research/issues/detail?id=155http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=18a8f0d9943369449bc4de92d411c78fb08d616chttp://lists.opensuse.org/opensuse-updates/2015-03/msg00091.htmlhttp://packetstormsecurity.com/files/134395/FreeType-2.5.3-Mac-FOND-Resource-Parsing-Out-Of-Bounds-Read-From-Stack.htmlhttp://www.debian.org/security/2015/dsa-3188http://www.mandriva.com/security/advisories?name=MDVSA-2015:055http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/72986http://www.ubuntu.com/usn/USN-2510-1http://www.ubuntu.com/usn/USN-2739-1https://security.gentoo.org/glsa/201503-05http://advisories.mageia.org/MGASA-2015-0083.htmlhttp://code.google.com/p/google-security-research/issues/detail?id=155http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=18a8f0d9943369449bc4de92d411c78fb08d616chttp://lists.opensuse.org/opensuse-updates/2015-03/msg00091.htmlhttp://packetstormsecurity.com/files/134395/FreeType-2.5.3-Mac-FOND-Resource-Parsing-Out-Of-Bounds-Read-From-Stack.htmlhttp://www.debian.org/security/2015/dsa-3188http://www.mandriva.com/security/advisories?name=MDVSA-2015:055http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/72986http://www.ubuntu.com/usn/USN-2510-1http://www.ubuntu.com/usn/USN-2739-1https://security.gentoo.org/glsa/201503-05
2015-02-08
Published