Vulnerability Name:

CVE-2014-9747 (CCN-114236)

Assigned:2015-09-11
Published:2015-09-11
Updated:2016-06-08
Summary:The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly update the current position for immediates-only mode, which allows remote attackers to cause a denial of service (infinite loop) via a Type42 font.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-399
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2014-9747

Source: CONFIRM
Type: UNKNOWN
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/tree/src/type42/t42parse.c?id=8b281f83e8516535756f92dbf90940ac44bd45e1

Source: DEBIAN
Type: UNKNOWN
DSA-3370

Source: CCN
Type: FreeType Web site
FreeType

Source: CCN
Type: IBM Security Bulletin T1024075 (Flex System Manager Node)
IBM Flex System Manager (FSM) is affected by multiple freetype2 vulnerabilities

Source: CCN
Type: oss-sec Mailing List, Fri, 11 Sep 2015 07:27:21 -0400
CVE Request: 2 FreeType issues

Source: MLIST
Type: UNKNOWN
[oss-security] 20150911 CVE Request: 2 FreeType issues

Source: MLIST
Type: UNKNOWN
[oss-security] 20150925 Re: CVE Request: 2 FreeType issues

Source: CCN
Type: BID-77018
FreeType CVE-2014-9747 Remote Denial Of Service Vulnerability

Source: XF
Type: UNKNOWN
freetype-cve20149747-dos(114236)

Source: MISC
Type: UNKNOWN
https://savannah.nongnu.org/bugs/?41309

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2014-9747

Vulnerable Configuration:Configuration 1:
  • cpe:/a:freetype:freetype:*:*:*:*:*:*:*:* (Version <= 2.5.3)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:freetype:freetype:2.5.3:*:*:*:*:*:*:*
  • AND
  • cpe:/h:ibm:flex_system_manager_node:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20149747
    V
    CVE-2014-9747
    2022-05-20
    oval:org.opensuse.security:def:33113
    P
    Security update for virglrenderer (Important) (in QA)
    2022-01-17
    oval:org.opensuse.security:def:30170
    P
    Security update for net-snmp (Important)
    2022-01-05
    oval:org.opensuse.security:def:35280
    P
    Security update for libqt4 (Important)
    2021-12-22
    oval:org.opensuse.security:def:33751
    P
    Security update for mozilla-nss (Important)
    2021-12-06
    oval:org.opensuse.security:def:33046
    P
    Security update for postgresql10 (Important)
    2021-11-22
    oval:org.opensuse.security:def:29440
    P
    Security update for transfig (Important)
    2021-10-29
    oval:org.opensuse.security:def:29429
    P
    Security update for libqt5-qtbase (Important)
    2021-09-30
    oval:org.opensuse.security:def:30131
    P
    Security update for python-urllib3 (Moderate)
    2021-09-29
    oval:org.opensuse.security:def:29428
    P
    Security update for python-urllib3 (Moderate)
    2021-09-29
    oval:org.opensuse.security:def:33007
    P
    Security update for curl (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:34521
    P
    Security update for spectre-meltdown-checker (Moderate)
    2021-08-27
    oval:org.opensuse.security:def:30233
    P
    Security update for fetchmail (Moderate)
    2021-08-18
    oval:org.opensuse.security:def:31231
    P
    Security update for the Linux Kernel (Important)
    2021-07-22
    oval:org.opensuse.security:def:32958
    P
    Security update for arpwatch (Important)
    2021-06-28
    oval:org.opensuse.security:def:33668
    P
    Security update for ucode-intel (Important)
    2021-06-10
    oval:org.opensuse.security:def:31187
    P
    Security update for the Linux Kernel (Live Patch 33 for SLE 12 SP3) (Important)
    2021-06-04
    oval:org.opensuse.security:def:30082
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:33910
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:34426
    P
    Security update for avahi (Moderate)
    2021-05-04
    oval:org.opensuse.security:def:34425
    P
    Security update for python36 (Moderate)
    2021-05-04
    oval:org.opensuse.security:def:30189
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:31166
    P
    Security update for tomcat (Important)
    2021-04-29
    oval:org.opensuse.security:def:32901
    P
    Security update for ImageMagick (Moderate)
    2021-04-20
    oval:org.opensuse.security:def:28964
    P
    Security update for MozillaFirefox (Important)
    2021-03-31
    oval:org.opensuse.security:def:33790
    P
    Security update for MozillaFirefox (Important)
    2021-03-31
    oval:org.opensuse.security:def:32284
    P
    Security update for openssl (Moderate)
    2021-03-24
    oval:org.opensuse.security:def:32283
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:34657
    P
    Security update for glib2 (Important)
    2021-03-16
    oval:org.opensuse.security:def:30027
    P
    Security update for java-1_7_1-ibm (Important)
    2021-02-18
    oval:org.opensuse.security:def:33764
    P
    Security update for openvswitch (Important)
    2021-02-15
    oval:org.opensuse.security:def:33069
    P
    Security update for python36 (Important)
    2021-02-10
    oval:org.opensuse.security:def:28915
    P
    Security update for dnsmasq (Important)
    2021-01-19
    oval:org.opensuse.security:def:34437
    P
    Security update for flac (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:35236
    P
    Security update for cyrus-sasl (Important)
    2020-12-28
    oval:org.opensuse.security:def:28861
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP2) (Important)
    2020-12-07
    oval:org.opensuse.security:def:35959
    P
    libnetpbm10-10.26.44-101.9.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35918
    P
    hyper-v-5-0.7.10 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:30427
    P
    Security update for xorg-x11-libs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27051
    P
    vte on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30416
    P
    Security update for xorg-x11-libXext
    2020-12-01
    oval:org.opensuse.security:def:26967
    P
    libpython2_6-1_0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29738
    P
    Security update for freetype2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30415
    P
    Security update for xorg-x11-libXdmcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26910
    P
    gstreamer-0_10-plugins-base on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29702
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:26829
    P
    systemtap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29064
    P
    Security update for bzip2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26701
    P
    ft2demos on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32745
    P
    lvm2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29020
    P
    Security update for resource-agents (Important)
    2020-12-01
    oval:org.opensuse.security:def:26637
    P
    ruby on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32658
    P
    evolution-data-server on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29003
    P
    Security update for rubygem-bundler
    2020-12-01
    oval:org.opensuse.security:def:34960
    P
    Security update for freetype2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26626
    P
    pam_mount on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32601
    P
    rsync on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34920
    P
    Security update for evince (Important)
    2020-12-01
    oval:org.opensuse.security:def:26625
    P
    pam_ldap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32507
    P
    evolution-data-server on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34282
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32372
    P
    Security update for tcpdump (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34238
    P
    Security update for policycoreutils (Low)
    2020-12-01
    oval:org.opensuse.security:def:32295
    P
    Security update for ppp (Important)
    2020-12-01
    oval:org.opensuse.security:def:28709
    P
    Security update for hplip
    2020-12-01
    oval:org.opensuse.security:def:34213
    P
    Security update for php5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28625
    P
    Security update for Image Magick
    2020-12-01
    oval:org.opensuse.security:def:34174
    P
    Security update for openssl1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30908
    P
    Security update for freetype2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28568
    P
    Security update for KVM
    2020-12-01
    oval:org.opensuse.security:def:34125
    P
    Security update for netpbm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30871
    P
    Security update for exempi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28483
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34067
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28352
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28285
    P
    Security update for mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33821
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:28274
    P
    Security update for mozilla-nss (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28273
    P
    Security update for mozilla-nspr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33532
    P
    Security update for xpdf
    2020-12-01
    oval:org.opensuse.security:def:33450
    P
    Security update for gmime
    2020-12-01
    oval:org.opensuse.security:def:29874
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:35209
    P
    Security update for libgcrypt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33439
    P
    Security update for ethereal and wireshark
    2020-12-01
    oval:org.opensuse.security:def:29788
    P
    Security update for gstreamer-0_10-plugins-base (Important)
    2020-12-01
    oval:org.opensuse.security:def:35170
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31907
    P
    Security update for freetype2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33438
    P
    Security update for dnsmasq
    2020-12-01
    oval:org.opensuse.security:def:29731
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:35121
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31869
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29644
    P
    Security update for cups (Important)
    2020-12-01
    oval:org.opensuse.security:def:35062
    P
    Security update for IBM Java
    2020-12-01
    oval:org.opensuse.security:def:29512
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34903
    P
    Security update for dhcpcd (Important)
    2020-12-01
    oval:org.opensuse.security:def:34813
    P
    Security update for php53
    2020-12-01
    oval:org.opensuse.security:def:34756
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31127
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:28074
    P
    Security update for freetype2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31078
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:28039
    P
    Security update for crash (Low)
    2020-12-01
    oval:org.opensuse.security:def:31022
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:27401
    P
    flac-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30867
    P
    Security update for evince (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27357
    P
    ImageMagick on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30780
    P
    Security update for bash (Low)
    2020-12-01
    oval:org.opensuse.security:def:27343
    P
    curl-openssl1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30723
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:27304
    P
    t1lib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30633
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:27255
    P
    opie on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30501
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:27202
    P
    libnewt0_52 on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.precise:def:20149747000
    V
    CVE-2014-9747 on Ubuntu 12.04 LTS (precise) - medium.
    2016-06-07
    oval:com.ubuntu.trusty:def:20149747000
    V
    CVE-2014-9747 on Ubuntu 14.04 LTS (trusty) - medium.
    2016-06-07
    oval:org.cisecurity:def:196
    P
    DSA-3370-1 -- freetype -- security update
    2016-02-08
    BACK
    freetype freetype *
    debian debian linux 7.0
    debian debian linux 8.0
    freetype freetype 2.5.3
    ibm flex system manager node *