Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Simon Bünzli

#49588de 53,638
5CVSS total
Vulnerabilidades · 1
PT-2015-4378
5.0
2014-03-11
Freetype · Freetype · CVE-2014-9745
**Name of the Vulnerable Software and Affected Versions** FreeType versions prior to 2.5.3 **Description** The issue allows remote attackers to cause a denial of service, specifically an infinite loop, by providing a "broken number-with-base" in a Postscript stream. This can be demonstrated with input such as '8#garbage'. **Recommendations** For versions prior to 2.5.3, update to version 2.5.3 or later to resolve the issue. As a temporary workaround, consider restricting the input to the parse encoding function to prevent the infinite loop.