Описание
cff/cf2intrp.c in the CFF CharString interpreter in FreeType before 2.5.4 proceeds with additional hints after the hint mask has been computed, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted OpenType font. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2240.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 2.5.2-2ubuntu3 |
| esm-infra-legacy/trusty | released | 2.5.2-1ubuntu2.4 |
| lucid | not-affected | code not present |
| precise | not-affected | code not present |
| trusty | released | 2.5.2-1ubuntu2.4 |
| trusty/esm | released | 2.5.2-1ubuntu2.4 |
| upstream | released | 2.5.4 |
| utopic | released | 2.5.2-2ubuntu1.1 |
Показывать по
EPSS
7.5 High
CVSS2
Связанные уязвимости
cff/cf2intrp.c in the CFF CharString interpreter in FreeType before 2.5.4 proceeds with additional hints after the hint mask has been computed, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted OpenType font. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2240.
cff/cf2intrp.c in the CFF CharString interpreter in FreeType before 2.5.4 proceeds with additional hints after the hint mask has been computed, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted OpenType font. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2240.
cff/cf2intrp.c in the CFF CharString interpreter in FreeType before 2. ...
cff/cf2intrp.c in the CFF CharString interpreter in FreeType before 2.5.4 proceeds with additional hints after the hint mask has been computed, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted OpenType font. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2240.
EPSS
7.5 High
CVSS2