« List of all CVEs

CVE-2014-9747

Published: 6/7/2016 Last updated: 8/6/2024 Reserved: 9/25/2015

The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly update the current position for immediates-only mode, which allows remote attackers to cause a denial of service (infinite loop) via a Type42 font.

CNA assigner: canonical (cc1ad9ee-3454-478d-9317-d3e869d708bc) Requested by: n/a

Opam packages affected (2)

conf-freetype conf-gd

Products affected (1)

Product Vendor Version
n/a n/a 10 for x64-based Systems

References (10)