CVE-2014-9670

Publication date 8 February 2015

Last updated 24 July 2024


Ubuntu priority

Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dereference, and application crash) via a crafted PCF file that specifies negative values for the first column and first row.

Status

Package Ubuntu Release Status
freetype 14.10 utopic
Fixed 2.5.2-2ubuntu1.1
14.04 LTS trusty
Fixed 2.5.2-1ubuntu2.4
12.04 LTS precise
Fixed 2.4.8-1ubuntu2.2
10.04 LTS lucid
Fixed 2.3.11-1ubuntu2.8

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
freetype

References

Related Ubuntu Security Notices (USN)

    • USN-2510-1
    • FreeType vulnerabilities
    • 24 February 2015

Other references