Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9747

Опубликовано: 22 янв. 2014
Источник: redhat
CVSS2: 2.1

Описание

The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly update the current position for immediates-only mode, which allows remote attackers to cause a denial of service (infinite loop) via a Type42 font.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5freetypeWill not fix
Red Hat Enterprise Linux 6freetypeWill not fix
Red Hat Enterprise Linux 7freetypeWill not fix

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1262373freetype: Use of uninitialized memory

2.1 Low

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly update the current position for immediates-only mode, which allows remote attackers to cause a denial of service (infinite loop) via a Type42 font.

CVSS3: 7.5
nvd
больше 9 лет назад

The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly update the current position for immediates-only mode, which allows remote attackers to cause a denial of service (infinite loop) via a Type42 font.

CVSS3: 7.5
debian
больше 9 лет назад

The t42_parse_encoding function in type42/t42parse.c in FreeType befor ...

CVSS3: 7.5
github
больше 3 лет назад

The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly update the current position for immediates-only mode, which allows remote attackers to cause a denial of service (infinite loop) via a Type42 font.

suse-cvrf
почти 10 лет назад

Security update for freetype2

2.1 Low

CVSS2