PT-2014-4577 · Freetype+1 · Freetype+1

Mateusz Jurczyk

·

Publicado

2014-03-11

·

Atualizado

2025-04-24

·

CVE-2014-2241

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FreeType versions prior to 2.5.3
Description The issue is related to the cf2 initLocalRegionBuffer and cf2 initGlobalRegionBuffer functions in cff/cf2ft.c, which do not properly check if a subroutine exists. This allows remote attackers to cause a denial of service (assertion failure) by using a crafted ttf file.
Recommendations For versions prior to 2.5.3, update to version 2.5.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of crafted ttf files to minimize the risk of exploitation.

Exploit

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1274
CVE-2014-2241
MGASA-2014-0130
OPENSUSE-SU-2024:10438-1
SUSE-SU-2025:20204-1

Produtos afetados

Alt Linux
Freetype