CVE-2014-9662: Buffer Overflow
cff/cf2ft.c in FreeType before 2.5.4 does not validate the return values of point-allocation functions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted OTF font.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9662?
CVE-2014-9662 has a moderate severity level due to its potential for causing a denial of service via heap-based buffer overflow.
How do I fix CVE-2014-9662?
To fix CVE-2014-9662, update FreeType to version 2.5.4 or later, which includes the necessary security patches.
Which software is affected by CVE-2014-9662?
CVE-2014-9662 affects FreeType versions prior to 2.5.4, and distributions such as openSUSE, Debian, and Ubuntu with specific versions are also impacted.
What types of attacks can CVE-2014-9662 expose my system to?
CVE-2014-9662 can allow remote attackers to cause denial of service or other unspecified impacts by exploiting a crafted OTF font.
Is there a known exploit for CVE-2014-9662?
While there is potential for exploitation, specific exploit code for CVE-2014-9662 is not publicly documented.