CVE-2014-2241
18.03.2014, 17:04
The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a subroutine exists, which allows remote attackers to cause a denial of service (assertion failure), as demonstrated by a crafted ttf file.Enginsight
| Vendor | Product | Version |
|---|---|---|
| freetype | freetype | 𝑥 ≤ 2.5.2 |
| freetype | freetype | 2.5 |
| freetype | freetype | 2.5.1 |
| canonical | ubuntu_linux | 13.10 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References