PublicDateAtUSN: 2015-02-08 Candidate: CVE-2014-9664 PublicDate: 2015-02-08 11:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9664 https://ubuntu.com/security/notices/USN-2510-1 Description: FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted Type42 font, related to type42/t42parse.c and type1/t1load.c. Ubuntu-Description: Notes: Bugs: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=777656 http://code.google.com/p/google-security-research/issues/detail?id=183 http://savannah.nongnu.org/bugs/?43655 Priority: medium Discovered-by: Mateusz Jurczyk Assigned-to: mdeslaur CVSS: Patches_freetype: upstream: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=dd89710f0f643eb0f99a3830e0712d26c7642acd upstream: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=73be9f9ab67842cfbec36ee99e8d2301434c84ca upstream_freetype: released (2.5.4) lucid_freetype: released (2.3.11-1ubuntu2.8) precise_freetype: released (2.4.8-1ubuntu2.2) trusty_freetype: released (2.5.2-1ubuntu2.4) trusty/esm_freetype: released (2.5.2-1ubuntu2.4) utopic_freetype: released (2.5.2-2ubuntu1.1) devel_freetype: released (2.5.2-2ubuntu3)