Lucene search

K
f5F5F5:K72372334
HistorySep 28, 2016 - 12:00 a.m.

K72372334 : FreeType vulnerability CVE-2014-9745

2016-09-2800:00:00
my.f5.com
16

7.4 High

AI Score

Confidence

High

0.066 Low

EPSS

Percentile

93.8%

Security Advisory Description

The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a “broken number-with-base” in a Postscript stream, as demonstrated by 8#garbage. (CVE-2014-9745)
Impact
A remote attacker may be able to cause a denial-of-service (DoS) attack for an ARX system via a crafted Postscript stream.

7.4 High

AI Score

Confidence

High

0.066 Low

EPSS

Percentile

93.8%