CVE-2014-9745
published 2015-09-14CVE-2014-9745: The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.73%
88.6th percentile
The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | freetype | < freetype 2.6-1 (bookworm) | freetype 2.6-1 (bookworm) |
| freetype | freetype | <= 2.5.2 | — |
| freetype | freetype | >= 0 < 2.6-1 | 2.6-1 |
| freetype | freetype | >= 0 < 2.6-1 | 2.6-1 |
| freetype | freetype | >= 0 < 2.6-1 | 2.6-1 |
| freetype | freetype | >= 0 < 2.6-1 | 2.6-1 |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FreeType vulnerabilities
vendor_ubuntu·2015-09-10
CVE-2014-9745 FreeType vulnerabilities
Title: FreeType vulnerabilities
Summary: Several security issues were fixed in FreeType.
It was discovered that FreeType did not correctly handle certain malformed
font files. If a user were tricked into using a specially crafted font
file, a remote attacker could cause FreeType to crash or hang, resulting in
a denial of service, or possibly expose uninitialized memory.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Red Hat
freetype: Infinite loop in parse_encoding in t1load.c
vendor_redhat·2014-02-14·CVSS 5.0
CVE-2014-9745 [MEDIUM] CWE-835 freetype: Infinite loop in parse_encoding in t1load.c
freetype: Infinite loop in parse_encoding in t1load.c
The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage.
Package: freetype (Red Hat Enterprise Linux 5) - Will not fix
Package: freetype (Red Hat Enterprise Linux 6) - Will not fix
Package: freetype (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2014-9745: freetype - The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows re...
vendor_debian·2014·CVSS 5.0
CVE-2014-9745 [MEDIUM] CVE-2014-9745: freetype - The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows re...
The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage.
Scope: local
bookworm: resolved (fixed in 2.6-1)
bullseye: resolved (fixed in 2.6-1)
forky: resolved (fixed in 2.6-1)
sid: resolved (fixed in 2.6-1)
trixie: resolved (fixed in 2.6-1)
GHSA
GHSA-62g3-xfgr-2wg5: The parse_encoding function in type1/t1load
ghsa_unreviewed·2022-05-14
CVE-2014-9745 [MEDIUM] GHSA-62g3-xfgr-2wg5: The parse_encoding function in type1/t1load
The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage.
OSV
CVE-2014-9745: The parse_encoding function in type1/t1load
osv·2015-09-14·CVSS 5.0
CVE-2014-9745 [MEDIUM] CVE-2014-9745: The parse_encoding function in type1/t1load
The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage.
No detection rules found.
No public exploits indexed.
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=df14e6c0b9592cbb24d5381dfc6106b14f915e75http://lists.opensuse.org/opensuse-updates/2015-10/msg00017.htmlhttp://savannah.nongnu.org/bugs/index.php?41590http://www.debian.org/security/2015/dsa-3370http://www.securityfocus.com/bid/76727http://www.securitytracker.com/id/1033536http://www.ubuntu.com/usn/USN-2739-1https://bugs.launchpad.net/ubuntu/+source/freetype/+bug/1492124https://code.google.com/p/chromium/issues/detail?id=459050http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=df14e6c0b9592cbb24d5381dfc6106b14f915e75http://lists.opensuse.org/opensuse-updates/2015-10/msg00017.htmlhttp://savannah.nongnu.org/bugs/index.php?41590http://www.debian.org/security/2015/dsa-3370http://www.securityfocus.com/bid/76727http://www.securitytracker.com/id/1033536http://www.ubuntu.com/usn/USN-2739-1https://bugs.launchpad.net/ubuntu/+source/freetype/+bug/1492124https://code.google.com/p/chromium/issues/detail?id=459050
2015-09-14
Published