CVE Vulnerabilities

CVE-2014-9745

Published: Sep 14, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a broken number-with-base in a Postscript stream, as demonstrated by 8#garbage.

Affected Software

NameVendorStart VersionEnd Version
FreetypeFreetype*2.5.2 (including)
FreetypeUbuntudevel*
FreetypeUbuntuesm-infra-legacy/trusty*
FreetypeUbuntuprecise*
FreetypeUbuntutrusty*
FreetypeUbuntutrusty/esm*
FreetypeUbuntuupstream*
FreetypeUbuntuvivid*
FreetypeUbuntuvivid/stable-phone-overlay*
FreetypeUbuntuvivid/ubuntu-core*

References