Wind River Support Network

HomeDefectsLIN6-11425
Fixed

LIN6-11425 : Security Advisory - freetype - CVE-2014-9746

Created: Jun 13, 2016    Updated: Dec 3, 2018
Resolved Date: Aug 25, 2016
Found In Version: 6.0.0.29
Fix Version: 6.0.0.31
Severity: Standard
Applicable for: Wind River Linux 6
Component/s: Userspace

Description

The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in type42/t42parse.c, and (4) ps_parser_load_field function in psaux/psobjs.c in FreeType before 2.5.4 do not check return values, which allows remote attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted font.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9746

Other Downloads


Live chat
Online