CVE-2014-9671
Published: 8 February 2015
Off-by-one error in the pcf_get_properties function in pcf/pcfread.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PCF file with a 0xffffffff size value that is improperly incremented.
Notes
Author | Note |
---|---|
mdeslaur | regression fixed in 2.5.5 |
Priority
Status
Package | Release | Status |
---|---|---|
freetype Launchpad, Ubuntu, Debian |
lucid |
Released
(2.3.11-1ubuntu2.8)
|
precise |
Released
(2.4.8-1ubuntu2.2)
|
|
trusty |
Released
(2.5.2-1ubuntu2.4)
|
|
upstream |
Released
(2.5.4)
|
|
utopic |
Released
(2.5.2-2ubuntu1.1)
|
|
Patches: upstream: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=0e2f5d518c60e2978f26400d110eff178fa7e3c3 upstream: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=74af85c4b62b35e55b0ce9dec55ee10cbc4962a2 upstream: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=06842c7b49c21f13c0ab61201daab6ff5a358fcc |