Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Simon Bünzli

#49588of 53,635
5Total CVSS
Vulnerabilities · 1
PT-2015-4378
5.0
2014-03-11
Freetype · Freetype · CVE-2014-9745
**Name of the Vulnerable Software and Affected Versions** FreeType versions prior to 2.5.3 **Description** The issue allows remote attackers to cause a denial of service, specifically an infinite loop, by providing a "broken number-with-base" in a Postscript stream. This can be demonstrated with input such as '8#garbage'. **Recommendations** For versions prior to 2.5.3, update to version 2.5.3 or later to resolve the issue. As a temporary workaround, consider restricting the input to the parse encoding function to prevent the infinite loop.