PT-2015-4378 · Freetype+3 · Freetype+3
Simon Bünzli
·
Publicado
2014-03-11
·
Atualizado
2018-10-30
·
CVE-2014-9745
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
FreeType versions prior to 2.5.3
Description
The issue allows remote attackers to cause a denial of service, specifically an infinite loop, by providing a "broken number-with-base" in a Postscript stream. This can be demonstrated with input such as '8#garbage'.
Recommendations
For versions prior to 2.5.3, update to version 2.5.3 or later to resolve the issue. As a temporary workaround, consider restricting the input to the parse encoding function to prevent the infinite loop.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Freetype
Suse
Ubuntu