CVE-2014-9657: High severity openSUSE openSUSE vulnerability
The ttfaceloadhdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9657?
CVE-2014-9657 has a severity rating that indicates it can lead to denial of service due to out-of-bounds read issues.
How do I fix CVE-2014-9657?
To fix CVE-2014-9657, update FreeType to version 2.5.4 or later.
Which software is affected by CVE-2014-9657?
CVE-2014-9657 affects multiple versions of FreeType and various Linux distributions including Red Hat, Ubuntu, and openSUSE.
What kind of attack can exploit CVE-2014-9657?
CVE-2014-9657 can be exploited by attackers using crafted TrueType fonts to cause denial of service.
Is CVE-2014-9657 related to any specific software vulnerabilities?
Yes, CVE-2014-9657 is specifically related to the tt_face_load_hdmx function in FreeType before version 2.5.4.