Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9662

Опубликовано: 24 нояб. 2014
Источник: redhat
CVSS2: 6.8

Описание

cff/cf2ft.c in FreeType before 2.5.4 does not validate the return values of point-allocation functions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted OTF font.

Отчет

Not vulnerable. This issue did not affect the versions of freetype as shipped with Red Hat Enterprise Linux 5, 6 and 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4freetypeNot affected
Red Hat Enterprise Linux 5freetypeNot affected
Red Hat Enterprise Linux 6freetypeNot affected
Red Hat Enterprise Linux 7freetypeNot affected
Red Hat Enterprise Virtualization 3mingw-virt-viewerNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1191084freetype: heap-based buffer overflow in cff/cf2ft.c

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

cff/cf2ft.c in FreeType before 2.5.4 does not validate the return values of point-allocation functions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted OTF font.

nvd
почти 11 лет назад

cff/cf2ft.c in FreeType before 2.5.4 does not validate the return values of point-allocation functions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted OTF font.

debian
почти 11 лет назад

cff/cf2ft.c in FreeType before 2.5.4 does not validate the return valu ...

github
больше 3 лет назад

cff/cf2ft.c in FreeType before 2.5.4 does not validate the return values of point-allocation functions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted OTF font.

suse-cvrf
почти 11 лет назад

Security update for freetype2

6.8 Medium

CVSS2