Bug 945849 - (CVE-2014-9745) VUL-0: CVE-2014-9745: freetype2: Infinite loop in parse_encoding in t1load.c
(CVE-2014-9745)
VUL-0: CVE-2014-9745: freetype2: Infinite loop in parse_encoding in t1load.c
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Minor
: ---
Assigned To: Fridrich Strba
Security Team bot
https://smash.suse.de/issue/156574/
CVSSv2:NVD:CVE-2014-9745:5.0:(AV:N/AC...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2015-09-15 10:31 UTC by Victor Pereira
Modified: 2017-08-10 14:00 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2015-09-15 10:31:48 UTC
rh#1262377

The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows
remote attackers to cause a denial of service (infinite loop) via a "broken
number-with-base" in a Postscript stream, as demonstrated by 8#garbage.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1262377
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9745
https://bugs.launchpad.net/ubuntu/+source/freetype/+bug/1492124
http://savannah.nongnu.org/bugs/index.php?41590
https://code.google.com/p/chromium/issues/detail?id=459050
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=df14e6c0b9592cbb24d5381dfc6106b14f915e75
http://www.ubuntu.com/usn/USN-2739-1
Comment 2 Swamp Workflow Management 2015-09-15 22:00:47 UTC
bugbot adjusting priority
Comment 4 Bernhard Wiedemann 2015-09-23 06:00:09 UTC
This is an autogenerated message for OBS integration:
This bug (945849) was mentioned in
https://build.opensuse.org/request/show/333066 13.1 / freetype2
Comment 7 Swamp Workflow Management 2015-10-07 13:54:57 UTC
An update workflow for this issue was started.
This issue was rated as low.
Please submit fixed packages until 2015-11-04.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/62306
Comment 8 Swamp Workflow Management 2015-10-09 07:10:38 UTC
openSUSE-SU-2015:1704-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 945849,947966
CVE References: CVE-2014-9745,CVE-2014-9747
Sources used:
openSUSE 13.1 (src):    freetype2-2.5.0.1-2.10.1, ft2demos-2.5.0-2.10.1
Comment 9 Swamp Workflow Management 2016-04-25 19:08:41 UTC
SUSE-SU-2016:1149-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 945849,947966
CVE References: CVE-2014-9745,CVE-2014-9747
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    freetype2-2.3.7-25.41.4
SUSE Linux Enterprise Server 11-SP4 (src):    freetype2-2.3.7-25.41.4, ft2demos-2.3.7-25.41.4
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    freetype2-2.3.7-25.41.4, ft2demos-2.3.7-25.41.4
Comment 10 Johannes Segitz 2017-08-10 14:00:08 UTC
fixed