CVE-2014-9668: Buffer Overflow
The woffopenfont function in sfnt/sfobjs.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting length values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact via a crafted Web Open Font Format (WOFF) file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9668?
CVE-2014-9668 has a severity rating that indicates potential denial of service through integer overflow and heap-based buffer overflow vulnerabilities.
How do I fix CVE-2014-9668?
To fix CVE-2014-9668, upgrade FreeType to version 2.5.4 or later on your affected systems.
Which software is affected by CVE-2014-9668?
CVE-2014-9668 affects FreeType versions up to and including 2.5.3 on specific releases of openSUSE, Fedora, and Ubuntu.
What is the impact of CVE-2014-9668?
The impact of CVE-2014-9668 includes possible denial of service due to heap-based buffer overflow and integer overflow vulnerabilities.
Is there a patch available for CVE-2014-9668?
Yes, a patch is available in the newer releases of FreeType, specifically in version 2.5.4 and later.