CVE-2014-9669: Integer Overflow
Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (out-of-bounds read or memory corruption) or possibly have unspecified other impact via a crafted cmap SFNT table.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9669?
The severity of CVE-2014-9669 is classified as important due to the potential for denial of service and memory corruption.
How do I fix CVE-2014-9669?
To fix CVE-2014-9669, update FreeType to version 2.5.4 or later, as this version addresses the integer overflow vulnerabilities.
What systems are affected by CVE-2014-9669?
CVE-2014-9669 affects multiple versions of FreeType prior to 2.5.4 and various Linux distributions including Ubuntu, Red Hat, and others.
What types of attacks can CVE-2014-9669 lead to?
CVE-2014-9669 can lead to out-of-bounds reads, memory corruption, and potential denial of service attacks.
Is there a workaround for CVE-2014-9669?
A temporary workaround for CVE-2014-9669 is to avoid processing untrusted or maliciously crafted SFNT files with FreeType until an update is applied.