HIGH · 7.5

CVE-2014-9674

The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values without validating the original values, which allows remote attackers to cause a den...

Vulnerability Description

The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values without validating the original values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact via a crafted Mac font.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
CanonicalUbuntu Linux10.04
OracleSolaris10.0
FedoraprojectFedora20
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Hpc Node6.0
RedhatEnterprise Linux Hpc Node Eus7.1
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Server Eus6.6.z
RedhatEnterprise Linux Workstation6.0
OpensuseOpensuse13.1
FreetypeFreetype<= 2.5.3

References

FAQ

What is CVE-2014-9674?

CVE-2014-9674 is a vulnerability with a CVSS score of 7.5 (HIGH). The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values without validating the original values, which allows remote attackers to cause a den...

How severe is CVE-2014-9674?

CVE-2014-9674 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-9674?

Check the references section above for vendor advisories and patch information. Affected products include: Canonical Ubuntu Linux, Oracle Solaris, Fedoraproject Fedora, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Hpc Node.