Release date:
Updated on:
Affected Systems:
FreeType <2.5.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66292
CVE (CAN) ID: CVE-2014-2241
FreeType is a popular font function library.
In versions earlier than FreeType 2.5.3, cff/cf 2ft. the cf2_initLocalRegionBuffer and cf2_initGlobalRegionBuffer functions in c do not correctly check whether a subroutine exists. This allows remote attackers to use a specially crafted ttf file to cause DoS (assertion failure ).
<* Source: Mateusz "j00ru" Jurczyk
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
FreeType
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.freetype.org/
Http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit? Id = 135c3faebb96f8f550bd4f318716f2e1e095a969
Http://savannah.nongnu.org/bugs? 41697