CVE-2014-9663: Buffer Overflow
The ttcmap4validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length field before that field's value is completely calculated, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted cmap SFNT table.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9663?
CVE-2014-9663 has a severity level that can potentially lead to a denial of service due to out-of-bounds read.
How do I fix CVE-2014-9663?
To mitigate CVE-2014-9663, you should upgrade FreeType to version 2.5.4 or later.
What software is affected by CVE-2014-9663?
CVE-2014-9663 affects FreeType versions prior to 2.5.4 as well as various Linux distributions using vulnerable versions.
What type of attack does CVE-2014-9663 allow?
CVE-2014-9663 allows attackers to exploit a crafted cmap S by causing a denial of service or potentially more severe impacts.
When was CVE-2014-9663 published?
CVE-2014-9663 was published in 2014 and has been affecting systems until patched by updates.