Vulnerability Name:

CVE-2014-9745 (CCN-106351)

Assigned:2015-09-10
Published:2015-09-10
Updated:2018-10-30
Summary:The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage.
CVSS v3 Severity:3.4 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L)
3.0 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
2.1 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:S/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-399
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2014-9745

Source: CCN
Type: FreeType GIT Repository
Fix Savannah bug #41309

Source: CONFIRM
Type: UNKNOWN
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=df14e6c0b9592cbb24d5381dfc6106b14f915e75

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2015:1704

Source: CONFIRM
Type: UNKNOWN
http://savannah.nongnu.org/bugs/index.php?41590

Source: CCN
Type: SECTRACK ID: 1033536
FreeType Bugs Let Remote Users Deny Service and Local Users Obtain Potentially Sensitive Information

Source: DEBIAN
Type: UNKNOWN
DSA-3370

Source: CCN
Type: IBM Security Bulletin T1024075 (Flex System Manager Node)
IBM Flex System Manager (FSM) is affected by multiple freetype2 vulnerabilities

Source: BID
Type: UNKNOWN
76727

Source: CCN
Type: BID-76727
FreeType 't1load.c' Denial of Service Vulnerability

Source: SECTRACK
Type: UNKNOWN
1033536

Source: UBUNTU
Type: UNKNOWN
USN-2739-1

Source: CCN
Type: USN-2739-1: FreeType vulnerabilities
Ubuntu Security Notice USN-2739-1

Source: CONFIRM
Type: UNKNOWN
https://bugs.launchpad.net/ubuntu/+source/freetype/+bug/1492124

Source: CONFIRM
Type: UNKNOWN
https://code.google.com/p/chromium/issues/detail?id=459050

Source: XF
Type: UNKNOWN
freetype-cve20149745-dos(106351)

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2014-9745

Vulnerable Configuration:Configuration 1:
  • cpe:/a:freetype:freetype:*:*:*:*:*:*:*:* (Version <= 2.5.2)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:opensuse:opensuse:13.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:freetype:freetype:2.5.2:*:*:*:*:*:*:*
  • AND
  • cpe:/h:ibm:flex_system_manager_node:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20149745
    V
    CVE-2014-9745
    2022-05-20
    oval:org.opensuse.security:def:33113
    P
    Security update for virglrenderer (Important) (in QA)
    2022-01-17
    oval:org.opensuse.security:def:30170
    P
    Security update for net-snmp (Important)
    2022-01-05
    oval:org.opensuse.security:def:35280
    P
    Security update for libqt4 (Important)
    2021-12-22
    oval:org.opensuse.security:def:33751
    P
    Security update for mozilla-nss (Important)
    2021-12-06
    oval:org.opensuse.security:def:33046
    P
    Security update for postgresql10 (Important)
    2021-11-22
    oval:org.opensuse.security:def:29440
    P
    Security update for transfig (Important)
    2021-10-29
    oval:org.opensuse.security:def:29429
    P
    Security update for libqt5-qtbase (Important)
    2021-09-30
    oval:org.opensuse.security:def:30131
    P
    Security update for python-urllib3 (Moderate)
    2021-09-29
    oval:org.opensuse.security:def:29428
    P
    Security update for python-urllib3 (Moderate)
    2021-09-29
    oval:org.opensuse.security:def:33007
    P
    Security update for curl (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:34521
    P
    Security update for spectre-meltdown-checker (Moderate)
    2021-08-27
    oval:org.opensuse.security:def:30233
    P
    Security update for fetchmail (Moderate)
    2021-08-18
    oval:org.opensuse.security:def:31231
    P
    Security update for the Linux Kernel (Important)
    2021-07-22
    oval:org.opensuse.security:def:32958
    P
    Security update for arpwatch (Important)
    2021-06-28
    oval:org.opensuse.security:def:33668
    P
    Security update for ucode-intel (Important)
    2021-06-10
    oval:org.opensuse.security:def:31187
    P
    Security update for the Linux Kernel (Live Patch 33 for SLE 12 SP3) (Important)
    2021-06-04
    oval:org.opensuse.security:def:30082
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:33910
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:34426
    P
    Security update for avahi (Moderate)
    2021-05-04
    oval:org.opensuse.security:def:34425
    P
    Security update for python36 (Moderate)
    2021-05-04
    oval:org.opensuse.security:def:30189
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:31166
    P
    Security update for tomcat (Important)
    2021-04-29
    oval:org.opensuse.security:def:32901
    P
    Security update for ImageMagick (Moderate)
    2021-04-20
    oval:org.opensuse.security:def:28964
    P
    Security update for MozillaFirefox (Important)
    2021-03-31
    oval:org.opensuse.security:def:33790
    P
    Security update for MozillaFirefox (Important)
    2021-03-31
    oval:org.opensuse.security:def:32284
    P
    Security update for openssl (Moderate)
    2021-03-24
    oval:org.opensuse.security:def:32283
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:34657
    P
    Security update for glib2 (Important)
    2021-03-16
    oval:org.opensuse.security:def:30027
    P
    Security update for java-1_7_1-ibm (Important)
    2021-02-18
    oval:org.opensuse.security:def:33764
    P
    Security update for openvswitch (Important)
    2021-02-15
    oval:org.opensuse.security:def:33069
    P
    Security update for python36 (Important)
    2021-02-10
    oval:org.opensuse.security:def:28915
    P
    Security update for dnsmasq (Important)
    2021-01-19
    oval:org.opensuse.security:def:34437
    P
    Security update for flac (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:35236
    P
    Security update for cyrus-sasl (Important)
    2020-12-28
    oval:org.opensuse.security:def:28861
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP2) (Important)
    2020-12-07
    oval:org.opensuse.security:def:35959
    P
    libnetpbm10-10.26.44-101.9.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35918
    P
    hyper-v-5-0.7.10 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:30427
    P
    Security update for xorg-x11-libs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27051
    P
    vte on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30416
    P
    Security update for xorg-x11-libXext
    2020-12-01
    oval:org.opensuse.security:def:26967
    P
    libpython2_6-1_0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29738
    P
    Security update for freetype2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30415
    P
    Security update for xorg-x11-libXdmcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26910
    P
    gstreamer-0_10-plugins-base on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29702
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:26829
    P
    systemtap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29064
    P
    Security update for bzip2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26701
    P
    ft2demos on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32745
    P
    lvm2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29020
    P
    Security update for resource-agents (Important)
    2020-12-01
    oval:org.opensuse.security:def:26637
    P
    ruby on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32658
    P
    evolution-data-server on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29003
    P
    Security update for rubygem-bundler
    2020-12-01
    oval:org.opensuse.security:def:34960
    P
    Security update for freetype2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26626
    P
    pam_mount on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32601
    P
    rsync on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34920
    P
    Security update for evince (Important)
    2020-12-01
    oval:org.opensuse.security:def:26625
    P
    pam_ldap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32507
    P
    evolution-data-server on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34282
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32372
    P
    Security update for tcpdump (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34238
    P
    Security update for policycoreutils (Low)
    2020-12-01
    oval:org.opensuse.security:def:32295
    P
    Security update for ppp (Important)
    2020-12-01
    oval:org.opensuse.security:def:28709
    P
    Security update for hplip
    2020-12-01
    oval:org.opensuse.security:def:34213
    P
    Security update for php5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28625
    P
    Security update for Image Magick
    2020-12-01
    oval:org.opensuse.security:def:34174
    P
    Security update for openssl1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30908
    P
    Security update for freetype2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28568
    P
    Security update for KVM
    2020-12-01
    oval:org.opensuse.security:def:34125
    P
    Security update for netpbm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30871
    P
    Security update for exempi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28483
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34067
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28352
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28285
    P
    Security update for mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33821
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:28274
    P
    Security update for mozilla-nss (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28273
    P
    Security update for mozilla-nspr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33532
    P
    Security update for xpdf
    2020-12-01
    oval:org.opensuse.security:def:33450
    P
    Security update for gmime
    2020-12-01
    oval:org.opensuse.security:def:29874
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:35209
    P
    Security update for libgcrypt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33439
    P
    Security update for ethereal and wireshark
    2020-12-01
    oval:org.opensuse.security:def:29788
    P
    Security update for gstreamer-0_10-plugins-base (Important)
    2020-12-01
    oval:org.opensuse.security:def:35170
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31907
    P
    Security update for freetype2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33438
    P
    Security update for dnsmasq
    2020-12-01
    oval:org.opensuse.security:def:29731
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:35121
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31869
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29644
    P
    Security update for cups (Important)
    2020-12-01
    oval:org.opensuse.security:def:35062
    P
    Security update for IBM Java
    2020-12-01
    oval:org.opensuse.security:def:29512
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34903
    P
    Security update for dhcpcd (Important)
    2020-12-01
    oval:org.opensuse.security:def:34813
    P
    Security update for php53
    2020-12-01
    oval:org.opensuse.security:def:34756
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31127
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:28074
    P
    Security update for freetype2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31078
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:28039
    P
    Security update for crash (Low)
    2020-12-01
    oval:org.opensuse.security:def:31022
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:27401
    P
    flac-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30867
    P
    Security update for evince (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27357
    P
    ImageMagick on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30780
    P
    Security update for bash (Low)
    2020-12-01
    oval:org.opensuse.security:def:27343
    P
    curl-openssl1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30723
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:27304
    P
    t1lib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30633
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:27255
    P
    opie on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30501
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:27202
    P
    libnewt0_52 on GA media (Moderate)
    2020-12-01
    oval:org.cisecurity:def:196
    P
    DSA-3370-1 -- freetype -- security update
    2016-02-08
    oval:com.ubuntu.precise:def:20149745000
    V
    CVE-2014-9745 on Ubuntu 12.04 LTS (precise) - low.
    2015-09-14
    oval:com.ubuntu.trusty:def:20149745000
    V
    CVE-2014-9745 on Ubuntu 14.04 LTS (trusty) - low.
    2015-09-14
    BACK
    freetype freetype *
    debian debian linux 7.0
    debian debian linux 8.0
    canonical ubuntu linux 12.04
    canonical ubuntu linux 14.04
    canonical ubuntu linux 15.04
    opensuse opensuse 13.1
    freetype freetype 2.5.2
    ibm flex system manager node *