CVE-2014-9674: Buffer Overflow
The MacReadPOSTResource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values without validating the original values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact via a crafted Mac font.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9674?
CVE-2014-9674 has been classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2014-9674?
To resolve CVE-2014-9674, update FreeType to version 2.5.4 or later.
What software versions are affected by CVE-2014-9674?
CVE-2014-9674 affects multiple versions of FreeType prior to 2.5.4 on Ubuntu, Fedora, Red Hat, and Oracle Solaris.
What type of attack does CVE-2014-9674 allow?
CVE-2014-9674 allows remote attackers to exploit integer overflow and heap-based buffer overflow vulnerabilities.
Is CVE-2014-9674 being actively exploited?
There are no specific reports indicating that CVE-2014-9674 is being actively exploited in the wild.