CVE Vulnerabilities

CVE-2014-9660

NULL Pointer Dereference

Published: Feb 08, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR record, which allows remote attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted BDF font.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Opensuse Opensuse 13.1 (including) 13.1 (including)
Opensuse Opensuse 13.2 (including) 13.2 (including)
Red Hat Enterprise Linux 6 RedHat freetype-0:2.3.11-15.el6_6.1 *
Red Hat Enterprise Linux 7 RedHat freetype-0:2.4.11-10.ael7b_1.1 *
Freetype Ubuntu devel *
Freetype Ubuntu esm-infra-legacy/trusty *
Freetype Ubuntu lucid *
Freetype Ubuntu precise *
Freetype Ubuntu trusty *
Freetype Ubuntu trusty/esm *
Freetype Ubuntu upstream *
Freetype Ubuntu utopic *

Potential Mitigations

References