CVE-2014-9666: Integer Overflow
The ttsbitdecoderinit function in sfnt/ttsbit.c in FreeType before 2.5.4 proceeds with a count-to-size association without restricting the count value, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted embedded bitmap.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9666?
CVE-2014-9666 has been classified as a denial of service vulnerability due to potential integer overflow and out-of-bounds read.
How do I fix CVE-2014-9666?
To fix CVE-2014-9666, upgrade FreeType to version 2.5.4 or later to mitigate the vulnerability.
What software is affected by CVE-2014-9666?
CVE-2014-9666 affects FreeType versions prior to 2.5.4 and various distributions including Ubuntu, Red Hat, Oracle Solaris, and Debian.
What impact can CVE-2014-9666 have?
CVE-2014-9666 can lead to a denial of service caused by an integer overflow and out-of-bounds read.
Is CVE-2014-9666 easy to exploit?
CVE-2014-9666 could be exploited by remote attackers, thus posing a significant risk to systems using vulnerable versions of FreeType.