CVE-2014-9659: Buffer Overflow
cff/cf2intrp.c in the CFF CharString interpreter in FreeType before 2.5.4 proceeds with additional hints after the hint mask has been computed, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted OpenType font. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2240.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9659?
CVE-2014-9659 has a critical severity level due to its potential for remote code execution and denial of service.
How do I fix CVE-2014-9659?
To fix CVE-2014-9659, upgrade FreeType to version 2.5.4 or later.
What exploit does CVE-2014-9659 enable?
CVE-2014-9659 enables remote attackers to execute arbitrary code or trigger a stack-based buffer overflow.
Which software is affected by CVE-2014-9659?
CVE-2014-9659 affects FreeType versions prior to 2.5.4 and certain Oracle Solaris, Fedora, openSUSE, and Ubuntu versions.
Can CVE-2014-9659 be exploited using crafted fonts?
Yes, CVE-2014-9659 can be exploited by attackers using specially crafted OpenType fonts.