Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9747

Опубликовано: 22 янв. 2014
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly update the current position for immediates-only mode, which allows remote attackers to cause a denial of service (infinite loop) via a Type42 font.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5freetypeWill not fix
Red Hat Enterprise Linux 6freetypeWill not fix
Red Hat Enterprise Linux 7freetypeWill not fix

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1262373freetype: Use of uninitialized memory

EPSS

Процентиль: 86%
0.03015
Низкий

2.1 Low

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 10 лет назад

The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly update the current position for immediates-only mode, which allows remote attackers to cause a denial of service (infinite loop) via a Type42 font.

CVSS3: 7.5
nvd
около 10 лет назад

The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly update the current position for immediates-only mode, which allows remote attackers to cause a denial of service (infinite loop) via a Type42 font.

CVSS3: 7.5
debian
около 10 лет назад

The t42_parse_encoding function in type42/t42parse.c in FreeType befor ...

CVSS3: 7.5
github
около 4 лет назад

The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly update the current position for immediates-only mode, which allows remote attackers to cause a denial of service (infinite loop) via a Type42 font.

suse-cvrf
больше 10 лет назад

Security update for freetype2

EPSS

Процентиль: 86%
0.03015
Низкий

2.1 Low

CVSS2