Bug 947966 - (CVE-2014-9746) VUL-1: CVE-2014-9746,CVE-2014-9747: The parse_encoding function in type1/t1load.c in FreeType before 2.5.3allows remote attackers to ca...
(CVE-2014-9746)
VUL-1: CVE-2014-9746,CVE-2014-9747: The parse_encoding function in type1/t1lo...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Minor
: ---
Assigned To: Fridrich Strba
Security Team bot
https://smash.suse.de/issue/157080/
CVSSv2:RedHat:CVE-2014-9747:2.1:(AV:L...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2015-09-29 09:28 UTC by Victor Pereira
Modified: 2017-08-10 14:39 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2015-09-29 09:28:16 UTC
CVE-2014-9747

The parse_encoding function in type1/t1load.c in FreeType before 2.5.3
allows remote attackers to cause a denial of service (infinite loop)
via a "broken number-with-base" in a Postscript stream, as demonstrated
by 8#garbage.


References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9747
http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-9747.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9747
Comment 2 Swamp Workflow Management 2015-09-29 22:00:17 UTC
bugbot adjusting priority
Comment 5 Bernhard Wiedemann 2015-09-30 10:00:22 UTC
This is an autogenerated message for OBS integration:
This bug (947966) was mentioned in
https://build.opensuse.org/request/show/334926 13.1 / freetype2
Comment 8 Swamp Workflow Management 2015-10-07 13:54:46 UTC
An update workflow for this issue was started.
This issue was rated as low.
Please submit fixed packages until 2015-11-04.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/62306
Comment 9 Swamp Workflow Management 2015-10-09 07:10:50 UTC
openSUSE-SU-2015:1704-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 945849,947966
CVE References: CVE-2014-9745,CVE-2014-9747
Sources used:
openSUSE 13.1 (src):    freetype2-2.5.0.1-2.10.1, ft2demos-2.5.0-2.10.1
Comment 10 Swamp Workflow Management 2016-04-25 19:08:51 UTC
SUSE-SU-2016:1149-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 945849,947966
CVE References: CVE-2014-9745,CVE-2014-9747
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    freetype2-2.3.7-25.41.4
SUSE Linux Enterprise Server 11-SP4 (src):    freetype2-2.3.7-25.41.4, ft2demos-2.3.7-25.41.4
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    freetype2-2.3.7-25.41.4, ft2demos-2.3.7-25.41.4
Comment 11 Andreas Stieger 2016-11-02 16:28:10 UTC
Also covers CVE-2014-9746 addressed by the same commit.

https://savannah.nongnu.org/bugs/?41309
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=8b281f83e8516535756f92dbf90940ac44bd45e1
https://bugs.launchpad.net/ubuntu/+source/freetype/+bug/1449225
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=798619

http://seclists.org/oss-sec/2015/q3/641

> 8b281f83e8516535756f92dbf90940ac44bd45e1 refers to four files in which
> return values aren't checked, and uninitialized memory can
> consequently be accessed. Use CVE-2014-9746 for all of those issues.
Comment 12 Johannes Segitz 2017-08-10 13:11:23 UTC
fixed