CVE-2014-9656: Buffer Overflow
Published Feb 8, 2015
·Updated
The ttsbitdecoderloadimage function in sfnt/ttsbit.c in FreeType before 2.5.4 does not properly check for an integer overflow, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted OpenType font.
Affected Software
11 affected components
Fedoraproject Fedora=20
Fedoraproject Fedora=21
FreeType FreeType<=2.5.3
Debian Debian Linux=7.0
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Canonical Ubuntu Linux=10.04
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=14.10
Canonical Ubuntu Linux=15.04
Event History
Feb 8, 2015
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9656?
CVE-2014-9656 has been classified as having a moderate severity due to potential denial of service and out-of-bounds read issues.
2
Which versions of FreeType are affected by CVE-2014-9656?
CVE-2014-9656 affects FreeType versions before 2.5.4.
3
How do I fix CVE-2014-9656?
To fix CVE-2014-9656, upgrade FreeType to version 2.5.4 or later.
4
Can CVE-2014-9656 be exploited remotely?
Yes, CVE-2014-9656 can be exploited remotely through the use of a crafted OpenType font.
5
What operating systems are impacted by CVE-2014-9656?
CVE-2014-9656 impacts several operating systems including Fedora, Ubuntu, Debian, and openSUSE.