CVE-2014-2240
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
12/03/2014
Last modified:
12/04/2025
Description
Stack-based buffer overflow in the cf2_hintmap_build function in cff/cf2hints.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of stem hints in a font file.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:* | 2.5.2 (including) | |
| cpe:2.3:a:freetype:freetype:1.3.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:freetype:freetype:2.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:freetype:freetype:2.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:freetype:freetype:2.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:freetype:freetype:2.0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:freetype:freetype:2.0.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:freetype:freetype:2.0.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:freetype:freetype:2.0.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:freetype:freetype:2.0.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:freetype:freetype:2.0.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:freetype:freetype:2.0.9:*:*:*:*:*:*:* | ||
| cpe:2.3:a:freetype:freetype:2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:freetype:freetype:2.1.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:freetype:freetype:2.1.4:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://savannah.nongnu.org/bugs/?41697=
- http://secunia.com/advisories/57291
- http://secunia.com/advisories/57447
- http://sourceforge.net/projects/freetype/files/freetype2/2.5.3
- http://www.freetype.org/index.html
- http://www.securityfocus.com/bid/66074
- http://www.securitytracker.com/id/1029895
- http://www.ubuntu.com/usn/USN-2148-1
- http://savannah.nongnu.org/bugs/?41697=
- http://secunia.com/advisories/57291
- http://secunia.com/advisories/57447
- http://sourceforge.net/projects/freetype/files/freetype2/2.5.3
- http://www.freetype.org/index.html
- http://www.securityfocus.com/bid/66074
- http://www.securitytracker.com/id/1029895
- http://www.ubuntu.com/usn/USN-2148-1



