Bugzilla – Bug 947966
VUL-1: CVE-2014-9746,CVE-2014-9747: The parse_encoding function in type1/t1load.c in FreeType before 2.5.3allows remote attackers to ca...
Last modified: 2017-08-10 14:39:02 UTC
CVE-2014-9747 The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9747 http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-9747.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9747
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (947966) was mentioned in https://build.opensuse.org/request/show/334926 13.1 / freetype2
An update workflow for this issue was started. This issue was rated as low. Please submit fixed packages until 2015-11-04. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/62306
openSUSE-SU-2015:1704-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 945849,947966 CVE References: CVE-2014-9745,CVE-2014-9747 Sources used: openSUSE 13.1 (src): freetype2-2.5.0.1-2.10.1, ft2demos-2.5.0-2.10.1
SUSE-SU-2016:1149-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 945849,947966 CVE References: CVE-2014-9745,CVE-2014-9747 Sources used: SUSE Linux Enterprise Software Development Kit 11-SP4 (src): freetype2-2.3.7-25.41.4 SUSE Linux Enterprise Server 11-SP4 (src): freetype2-2.3.7-25.41.4, ft2demos-2.3.7-25.41.4 SUSE Linux Enterprise Debuginfo 11-SP4 (src): freetype2-2.3.7-25.41.4, ft2demos-2.3.7-25.41.4
Also covers CVE-2014-9746 addressed by the same commit. https://savannah.nongnu.org/bugs/?41309 http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=8b281f83e8516535756f92dbf90940ac44bd45e1 https://bugs.launchpad.net/ubuntu/+source/freetype/+bug/1449225 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=798619 http://seclists.org/oss-sec/2015/q3/641 > 8b281f83e8516535756f92dbf90940ac44bd45e1 refers to four files in which > return values aren't checked, and uninitialized memory can > consequently be accessed. Use CVE-2014-9746 for all of those issues.
fixed