PT-2016-3507 · Freetype+2 · Freetype+2

J00Ru

+1

·

Published

2014-12-07

·

Updated

2016-06-08

·

CVE-2014-9747

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions FreeType versions prior to 2.5.4
Description The issue concerns the t42 parse encoding function in type42/t42parse.c, which does not properly update the current position for immediates-only mode. This allows remote attackers to cause a denial of service, specifically an infinite loop, by providing a Type42 font.
Recommendations For versions prior to 2.5.4, update to version 2.5.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of Type42 fonts until the update is applied.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2420
CVE-2014-9747
DLA-319-1
DSA-3370-1
SUSE-SU-2016:1149-1
USN-2739-1

Affected Products

Alt Linux
Freetype
Suse