The woff_open_font function in sfnt/sfobjs.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting length values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact via a crafted Web Open Font Format (WOFF) file.

Project Subscriptions

Vendors Products
Canonical Subscribe
Ubuntu Linux Subscribe
Fedoraproject Subscribe
Freetype Subscribe
Freetype Subscribe
Opensuse Subscribe
Opensuse Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2014-9478 The woff_open_font function in sfnt/sfobjs.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting length values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact via a crafted Web Open Font Format (WOFF) file.
Ubuntu USN Ubuntu USN USN-2510-1 FreeType vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T13:55:02.949Z

Reserved: 2015-02-07T00:00:00

Link: CVE-2014-9668

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2015-02-08T11:59:29.977

Modified: 2025-04-12T10:46:40.837

Link: CVE-2014-9668

cve-icon Redhat

Severity : Important

Publid Date: 2014-11-24T00:00:00Z

Links: CVE-2014-9668 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses