Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9745

Опубликовано: 14 фев. 2014
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5freetypeWill not fix
Red Hat Enterprise Linux 6freetypeWill not fix
Red Hat Enterprise Linux 7freetypeWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1262377freetype: Infinite loop in parse_encoding in t1load.c

EPSS

Процентиль: 85%
0.02361
Низкий

2.1 Low

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage.

nvd
больше 10 лет назад

The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage.

debian
больше 10 лет назад

The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 ...

github
больше 3 лет назад

The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage.

suse-cvrf
почти 10 лет назад

Security update for freetype2

EPSS

Процентиль: 85%
0.02361
Низкий

2.1 Low

CVSS2