Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-2241

Overview

Vulnerability Score 6.8 6.8
CVE Id CVE-2014-2241
Last Modified 01 Apr 2014 02:29:28
Published 18 Mar 2014 01:04:18
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2014-2241

Summary

The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a subroutine exists, which allows remote attackers to cause a denial of service (assertion failure), as demonstrated by a crafted ttf file.

Vulnerable Systems

Operating System

  • Canonical Ubuntu Linux 13.10

Application

  • Freetype 2.5

  • Freetype 2.5.1

  • Freetype 2.5.2


References

UBUNTU - USN-2148-1

MLIST - [oss-security] 20140312 Re: Two stack-based issues in freetype [NOT a request]

CONFIRM - http://savannah.nongnu.org/bugs/?41697

CONFIRM - http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=135c3faebb96f8f550bd4f318716f2e1e095a969

SECUNIA - 57447


Last Updated: 27 May 2016 11:04:44