CVE-2014-9745

Publication date 14 September 2015

Last updated 24 July 2024


Ubuntu priority

The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage.

Status

Package Ubuntu Release Status
freetype 15.04 vivid
Fixed 2.5.2-2ubuntu3.1
14.04 LTS trusty
Fixed 2.5.2-1ubuntu2.5
12.04 LTS precise
Fixed 2.4.8-1ubuntu2.3

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
freetype

References

Related Ubuntu Security Notices (USN)

    • USN-2739-1
    • FreeType vulnerabilities
    • 10 September 2015

Other references