CVE-2014-9656

The tt_sbit_decoder_load_image function in sfnt/ttsbit.c in FreeType before 2.5.4 does not properly check for an integer overflow, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted OpenType font.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
Affected Products (NVD)
VendorProductVersion
freetypefreetype
𝑥
≤ 2.5.3
debiandebian_linux
7.0
opensuseopensuse
13.1
opensuseopensuse
13.2
canonicalubuntu_linux
10.04
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
14.10
canonicalubuntu_linux
15.04
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
freetype
bookworm
2.12.1+dfsg-5+deb12u3
fixed
bullseye
2.10.4+dfsg-1+deb11u1
fixed
sid
2.13.3+dfsg-1
fixed
trixie
2.13.3+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
freetype
lucid
Fixed 2.3.11-1ubuntu2.8
released
precise
Fixed 2.4.8-1ubuntu2.2
released
trusty
Fixed 2.5.2-1ubuntu2.4
released
utopic
Fixed 2.5.2-2ubuntu1.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
freetype2-devel
suse enterprise desktop 15
2.9-2.13
fixed
suse enterprise desktop 15 SP1
2.9-2.13
fixed
suse enterprise desktop 15 SP2
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP3
2.10.1-4.8.1
fixed
suse enterprise desktop 15 SP4
2.10.1-4.8.1
fixed
suse enterprise desktop 15 SP5
2.10.4-150000.4.12.1
fixed
suse enterprise desktop 15 SP6
2.10.4-150000.4.15.1
fixed
suse enterprise desktop 15 SP7
2.10.4-150000.4.22.1
fixed
suse enterprise sap 15
2.9-2.13
fixed
suse enterprise sap 15 SP1
2.9-2.13
fixed
suse enterprise sap 15 SP2
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP3
2.10.1-4.8.1
fixed
suse enterprise sap 15 SP4
2.10.1-4.8.1
fixed
suse enterprise sap 15 SP5
2.10.4-150000.4.12.1
fixed
suse enterprise sap 15 SP6
2.10.4-150000.4.15.1
fixed
suse enterprise sap 15 SP7
2.10.4-150000.4.22.1
fixed
suse enterprise server 15
2.9-2.13
fixed
suse enterprise server 15 SP1
2.9-2.13
fixed
suse enterprise server 15 SP2
2.10.1-4.3.1
fixed
suse enterprise server 15 SP3
2.10.1-4.8.1
fixed
suse enterprise server 15 SP4
2.10.1-4.8.1
fixed
suse enterprise server 15 SP5
2.10.4-150000.4.12.1
fixed
suse enterprise server 15 SP6
2.10.4-150000.4.15.1
fixed
suse enterprise server 15 SP7
2.10.4-150000.4.22.1
fixed
ft2demos
suse enterprise sap 12
2.5.3-5.1
fixed
suse enterprise sap 12 SP5
2.6.3-7.15.1
fixed
suse enterprise server 12
2.5.3-5.1
fixed
suse enterprise server 12 SP4
2.6.3-7.15.1
fixed
suse enterprise server 12 SP5
2.6.3-7.15.1
fixed
libfreetype6
suse enterprise desktop 15
2.9-2.13
fixed
suse enterprise desktop 15 SP1
2.9-2.13
fixed
suse enterprise desktop 15 SP2
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP3
2.10.1-4.8.1
fixed
suse enterprise desktop 15 SP4
2.10.1-4.8.1
fixed
suse enterprise desktop 15 SP5
2.10.4-150000.4.12.1
fixed
suse enterprise desktop 15 SP6
2.10.4-150000.4.15.1
fixed
suse enterprise desktop 15 SP7
2.10.4-150000.4.22.1
fixed
suse enterprise sap 12
2.5.3-5.1
fixed
suse enterprise sap 12 SP5
2.6.3-7.15.1
fixed
suse enterprise sap 15
2.9-2.13
fixed
suse enterprise sap 15 SP1
2.9-2.13
fixed
suse enterprise sap 15 SP2
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP3
2.10.1-4.8.1
fixed
suse enterprise sap 15 SP4
2.10.1-4.8.1
fixed
suse enterprise sap 15 SP5
2.10.4-150000.4.12.1
fixed
suse enterprise sap 15 SP6
2.10.4-150000.4.15.1
fixed
suse enterprise sap 15 SP7
2.10.4-150000.4.22.1
fixed
suse enterprise server 12
2.5.3-5.1
fixed
suse enterprise server 12 SP4
2.6.3-7.15.1
fixed
suse enterprise server 12 SP5
2.6.3-7.15.1
fixed
suse enterprise server 15
2.9-2.13
fixed
suse enterprise server 15 SP1
2.9-2.13
fixed
suse enterprise server 15 SP2
2.10.1-4.3.1
fixed
suse enterprise server 15 SP3
2.10.1-4.8.1
fixed
suse enterprise server 15 SP4
2.10.1-4.8.1
fixed
suse enterprise server 15 SP5
2.10.4-150000.4.12.1
fixed
suse enterprise server 15 SP6
2.10.4-150000.4.15.1
fixed
suse enterprise server 15 SP7
2.10.4-150000.4.22.1
fixed
libfreetype6-32bit
suse enterprise desktop 15
2.9-2.13
fixed
suse enterprise desktop 15 SP1
2.9-2.13
fixed
suse enterprise desktop 15 SP2
2.10.1-4.3.1
fixed
suse enterprise desktop 15 SP3
2.10.1-4.8.1
fixed
suse enterprise desktop 15 SP4
2.10.1-4.8.1
fixed
suse enterprise desktop 15 SP5
2.10.4-150000.4.12.1
fixed
suse enterprise desktop 15 SP6
2.10.4-150000.4.15.1
fixed
suse enterprise desktop 15 SP7
2.10.4-150000.4.22.1
fixed
suse enterprise sap 12
2.5.3-5.1
fixed
suse enterprise sap 12 SP5
2.6.3-7.15.1
fixed
suse enterprise sap 15
2.9-2.13
fixed
suse enterprise sap 15 SP1
2.9-2.13
fixed
suse enterprise sap 15 SP2
2.10.1-4.3.1
fixed
suse enterprise sap 15 SP3
2.10.1-4.8.1
fixed
suse enterprise sap 15 SP4
2.10.1-4.8.1
fixed
suse enterprise sap 15 SP5
2.10.4-150000.4.12.1
fixed
suse enterprise sap 15 SP6
2.10.4-150000.4.15.1
fixed
suse enterprise sap 15 SP7
2.10.4-150000.4.22.1
fixed
suse enterprise server 12
2.5.3-5.1
fixed
suse enterprise server 12 SP4
2.6.3-7.15.1
fixed
suse enterprise server 12 SP5
2.6.3-7.15.1
fixed
suse enterprise server 15
2.9-2.13
fixed
suse enterprise server 15 SP1
2.9-2.13
fixed
suse enterprise server 15 SP2
2.10.1-4.3.1
fixed
suse enterprise server 15 SP3
2.10.1-4.8.1
fixed
suse enterprise server 15 SP4
2.10.1-4.8.1
fixed
suse enterprise server 15 SP5
2.10.4-150000.4.12.1
fixed
suse enterprise server 15 SP6
2.10.4-150000.4.15.1
fixed
suse enterprise server 15 SP7
2.10.4-150000.4.22.1
fixed
References