CVE-2014-9658: High severity Oracle Solaris vulnerability
The ttfaceloadkern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9658?
CVE-2014-9658 has a severity rating that indicates a potential denial of service due to an out-of-bounds read in FreeType.
How do I fix CVE-2014-9658?
To fix CVE-2014-9658, you should upgrade FreeType to version 2.5.4 or later.
What software is affected by CVE-2014-9658?
CVE-2014-9658 affects various versions of FreeType prior to 2.5.4 and several Linux distributions including Ubuntu, Fedora, and Red Hat.
What is the impact of CVE-2014-9658?
CVE-2014-9658 can cause a denial of service through an out-of-bounds read, potentially leading to application crashes.
Who is responsible for the CVE-2014-9658 vulnerability?
The CVE-2014-9658 vulnerability was discovered in the FreeType library, specifically in the tt_face_load_kern function.