CVE-2014-9661: Use After Free
type42/t42parse.c in FreeType before 2.5.4 does not consider that scanning can be incomplete without triggering an error, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted Type42 font.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9661?
CVE-2014-9661 is classified as a denial of service vulnerability that can result in a use-after-free condition.
How do I fix CVE-2014-9661?
To fix CVE-2014-9661, upgrade to FreeType version 2.5.4 or later.
Which versions are affected by CVE-2014-9661?
CVE-2014-9661 affects FreeType versions before 2.5.4 and various Linux distributions that are using those versions.
Can CVE-2014-9661 lead to other impacts besides denial of service?
Yes, CVE-2014-9661 may potentially allow for unspecified other impacts due to the nature of the vulnerability.
Is CVE-2014-9661 specific to any operating system?
CVE-2014-9661 primarily affects Linux distributions including Ubuntu, Debian, CentOS, and Fedora.