CVE-2014-9745: Medium severity FreeType FreeType vulnerability
Published Sep 14, 2015
·Updated
The parseencoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage.
Affected Software
7 affected components
FreeType FreeType<=2.5.2
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.04
openSUSE openSUSE=13.1
Event History
Sep 14, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9745?
CVE-2014-9745 has a high severity rating due to its potential for denial of service through an infinite loop.
2
How do I fix CVE-2014-9745?
To fix CVE-2014-9745, update FreeType to version 2.5.3 or higher.
3
What systems are affected by CVE-2014-9745?
CVE-2014-9745 affects FreeType versions prior to 2.5.3 and several specific distributions of Debian and Ubuntu Linux.
4
Can CVE-2014-9745 be exploited remotely?
Yes, CVE-2014-9745 can be exploited remotely via a malformed Postscript stream.
5
What type of attack is CVE-2014-9745 associated with?
CVE-2014-9745 is associated with denial of service attacks caused by an infinite loop.