Bugzilla – Bug 916873
VUL-0: CVE-2014-9672: freetype2: Array index error in the parse_fond function in base/ftmac.c
Last modified: 2019-05-22 01:02:21 UTC
CVE-2014-9672 Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information from process memory via a crafted FOND resource in a Mac font file. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9672 http://code.google.com/p/google-security-research/issues/detail?id=155 http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=18a8f0d9943369449bc4de92d411c78fb08d616c
bugbot adjusting priority
An update workflow for this issue was started. This issue was rated as moderate. Please submit fixed packages until 2015-02-25. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/60646
This is an autogenerated message for OBS integration: This bug (916873) was mentioned in https://build.opensuse.org/request/show/286989 13.2 / freetype2 https://build.opensuse.org/request/show/286990 13.1 / freetype2
SUSE-SU-2015:0455-1: An update that fixes 21 vulnerabilities is now available. Category: security (moderate) Bug References: 916847,916856,916857,916858,916859,916860,916861,916862,916863,916864,916865,916867,916868,916870,916871,916872,916873,916874,916879,916881 CVE References: CVE-2014-2240,CVE-2014-9656,CVE-2014-9657,CVE-2014-9658,CVE-2014-9659,CVE-2014-9660,CVE-2014-9661,CVE-2014-9662,CVE-2014-9663,CVE-2014-9664,CVE-2014-9665,CVE-2014-9666,CVE-2014-9667,CVE-2014-9668,CVE-2014-9669,CVE-2014-9670,CVE-2014-9671,CVE-2014-9672,CVE-2014-9673,CVE-2014-9674,CVE-2014-9675 Sources used: SUSE Linux Enterprise Software Development Kit 12 (src): freetype2-2.5.3-5.1 SUSE Linux Enterprise Server 12 (src): freetype2-2.5.3-5.1 SUSE Linux Enterprise Desktop 12 (src): freetype2-2.5.3-5.1
SUSE-SU-2015:0463-1: An update that fixes 20 vulnerabilities is now available. Category: security (moderate) Bug References: 916856,916857,916858,916859,916861,916863,916864,916865,916870,916871,916872,916873,916874,916879,916881 CVE References: CVE-2014-9656,CVE-2014-9657,CVE-2014-9658,CVE-2014-9659,CVE-2014-9660,CVE-2014-9661,CVE-2014-9662,CVE-2014-9663,CVE-2014-9664,CVE-2014-9665,CVE-2014-9666,CVE-2014-9667,CVE-2014-9668,CVE-2014-9669,CVE-2014-9670,CVE-2014-9671,CVE-2014-9672,CVE-2014-9673,CVE-2014-9674,CVE-2014-9675 Sources used: SUSE Linux Enterprise Software Development Kit 11 SP3 (src): freetype2-2.3.7-25.34.1 SUSE Linux Enterprise Server 11 SP3 for VMware (src): freetype2-2.3.7-25.34.1, ft2demos-2.3.7-25.34.1 SUSE Linux Enterprise Server 11 SP3 (src): freetype2-2.3.7-25.34.1, ft2demos-2.3.7-25.34.1 SUSE Linux Enterprise Desktop 11 SP3 (src): freetype2-2.3.7-25.34.1, ft2demos-2.3.7-25.34.1
This is an autogenerated message for OBS integration: This bug (916873) was mentioned in https://build.opensuse.org/request/show/292048 13.2 / freetype2 https://build.opensuse.org/request/show/292049 13.1 / freetype2
released
openSUSE-SU-2015:0627-1: An update that fixes 20 vulnerabilities is now available. Category: security (moderate) Bug References: 916847,916856,916857,916858,916859,916860,916861,916862,916863,916864,916865,916867,916868,916870,916871,916872,916873,916874,916879,916881 CVE References: CVE-2014-9656,CVE-2014-9657,CVE-2014-9658,CVE-2014-9659,CVE-2014-9660,CVE-2014-9661,CVE-2014-9662,CVE-2014-9663,CVE-2014-9664,CVE-2014-9665,CVE-2014-9666,CVE-2014-9667,CVE-2014-9668,CVE-2014-9669,CVE-2014-9670,CVE-2014-9671,CVE-2014-9672,CVE-2014-9673,CVE-2014-9674,CVE-2014-9675 Sources used: openSUSE 13.2 (src): freetype2-2.5.3-2.4.1, ft2demos-2.5.3-2.4.1 openSUSE 13.1 (src): freetype2-2.5.0.1-2.4.1, ft2demos-2.5.0-2.4.1