Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9662

Опубликовано: 24 нояб. 2014
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

cff/cf2ft.c in FreeType before 2.5.4 does not validate the return values of point-allocation functions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted OTF font.

Отчет

Not vulnerable. This issue did not affect the versions of freetype as shipped with Red Hat Enterprise Linux 5, 6 and 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4freetypeNot affected
Red Hat Enterprise Linux 5freetypeNot affected
Red Hat Enterprise Linux 6freetypeNot affected
Red Hat Enterprise Linux 7freetypeNot affected
Red Hat Enterprise Virtualization 3mingw-virt-viewerNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1191084freetype: heap-based buffer overflow in cff/cf2ft.c

EPSS

Процентиль: 90%
0.04321
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

cff/cf2ft.c in FreeType before 2.5.4 does not validate the return values of point-allocation functions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted OTF font.

nvd
больше 11 лет назад

cff/cf2ft.c in FreeType before 2.5.4 does not validate the return values of point-allocation functions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted OTF font.

debian
больше 11 лет назад

cff/cf2ft.c in FreeType before 2.5.4 does not validate the return valu ...

github
больше 4 лет назад

cff/cf2ft.c in FreeType before 2.5.4 does not validate the return values of point-allocation functions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted OTF font.

suse-cvrf
больше 11 лет назад

Security update for freetype2

EPSS

Процентиль: 90%
0.04321
Низкий

6.8 Medium

CVSS2