CVE-2014-9673: Buffer Overflow
Integer signedness error in the MacReadPOSTResource function in base/ftobjs.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted Mac font.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9673?
CVE-2014-9673 has a high severity as it can lead to a denial of service through a heap-based buffer overflow.
How do I fix CVE-2014-9673?
To fix CVE-2014-9673, update FreeType to version 2.5.4 or later.
Which software versions are affected by CVE-2014-9673?
CVE-2014-9673 affects FreeType versions prior to 2.5.4 on multiple Linux distributions including Ubuntu, Debian, and Red Hat.
What impact can CVE-2014-9673 have on my system?
CVE-2014-9673 can result in a denial of service or potentially unspecified other impacts due to remote exploitation.
Is CVE-2014-9673 exploitable remotely?
Yes, an attacker can exploit CVE-2014-9673 remotely using a crafted Mac font to cause vulnerabilities in affected systems.