Your submission was sent successfully! Close

CVE-2014-9673

Published: 8 February 2015

Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted Mac font.

Priority

Medium

Status

Package Release Status
freetype
Launchpad, Ubuntu, Debian
lucid
Released (2.3.11-1ubuntu2.8)
precise
Released (2.4.8-1ubuntu2.2)
trusty
Released (2.5.2-1ubuntu2.4)
upstream
Released (2.5.4)
utopic
Released (2.5.2-2ubuntu1.1)
Patches:
upstream: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=35252ae9aa1dd9343e9f4884e9ddb1fee10ef415