ALT-PU-2014-1274-1
Package libfreetype updated to version 2.5.3-alt1 for branch sisyphus in task 116236.
Closed vulnerabilities
BDU:2015-09767
Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
Modified: 2024-11-21
CVE-2014-2240
Stack-based buffer overflow in the cf2_hintmap_build function in cff/cf2hints.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of stem hints in a font file.
- http://savannah.nongnu.org/bugs/?41697
- http://savannah.nongnu.org/bugs/?41697
- 57291
- 57291
- 57447
- 57447
- http://sourceforge.net/projects/freetype/files/freetype2/2.5.3
- http://sourceforge.net/projects/freetype/files/freetype2/2.5.3
- http://www.freetype.org/index.html
- http://www.freetype.org/index.html
- 66074
- 66074
- 1029895
- 1029895
- USN-2148-1
- USN-2148-1
Modified: 2024-11-21
CVE-2014-2241
The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a subroutine exists, which allows remote attackers to cause a denial of service (assertion failure), as demonstrated by a crafted ttf file.
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=135c3faebb96f8f550bd4f318716f2e1e095a969
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=135c3faebb96f8f550bd4f318716f2e1e095a969
- http://savannah.nongnu.org/bugs/?41697
- http://savannah.nongnu.org/bugs/?41697
- 57447
- 57447
- [oss-security] 20140312 Re: Two stack-based issues in freetype [NOT a request]
- [oss-security] 20140312 Re: Two stack-based issues in freetype [NOT a request]
- USN-2148-1
- USN-2148-1
Modified: 2024-11-21
CVE-2014-9745
The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage.
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=df14e6c0b9592cbb24d5381dfc6106b14f915e75
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=df14e6c0b9592cbb24d5381dfc6106b14f915e75
- openSUSE-SU-2015:1704
- openSUSE-SU-2015:1704
- http://savannah.nongnu.org/bugs/index.php?41590
- http://savannah.nongnu.org/bugs/index.php?41590
- DSA-3370
- DSA-3370
- 76727
- 76727
- 1033536
- 1033536
- USN-2739-1
- USN-2739-1
- https://bugs.launchpad.net/ubuntu/+source/freetype/+bug/1492124
- https://bugs.launchpad.net/ubuntu/+source/freetype/+bug/1492124
- https://code.google.com/p/chromium/issues/detail?id=459050
- https://code.google.com/p/chromium/issues/detail?id=459050