The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in type42/t42parse.c, and (4) ps_parser_load_field function in psaux/psobjs.c in FreeType before 2.5.4 do not check return values, which allows remote attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted font.
References
Configurations
History
No history.
Information
Published : 2016-06-07 14:06
Updated : 2024-02-04 18:53
NVD link : CVE-2014-9746
Mitre link : CVE-2014-9746
CVE.ORG link : CVE-2014-9746
JSON object : View
Products Affected
debian
- debian_linux
freetype
- freetype
CWE
CWE-20
Improper Input Validation