6.8

CVE-2014-2241

Exploit
The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a subroutine exists, which allows remote attackers to cause a denial of service (assertion failure), as demonstrated by a crafted ttf file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Freetype ≫ Freetype Version <= 2.5.2
Freetype ≫ Freetype Version 2.5
Freetype ≫ Freetype Version 2.5.1
Canonical ≫ Ubuntu Linux Version 13.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.57% 0.722
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://savannah.nongnu.org/bugs/?41697
http://secunia.com/advisories/57447
http://www.ubuntu.com/usn/USN-2148-1
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=135c3faebb96f8f550bd4f318716f2e1e095a969
Patch
Exploit
http://www.openwall.com/lists/oss-security/2014/03/12/4