Synced 19 Jun 2026 07:34 UTC Account
← All products

CVE-2014-9672

MEDIUM severity · CVSS 5.8 · Memory corruption
5.8CVSS MEDIUM

Summary

Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information from process memory via a crafted FOND resource in a Mac font file.

Impact & exploitability

Attack vectorNetwork
Attack complexity
Privileges required
User interaction
Confidentiality impact
Integrity impactNone
Availability impact
Exploit probability (EPSS)5%

AV:N/AC:M/Au:N/C:P/I:N/A:P

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Official patch: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=18a8f0d9943369449bc4de92d411c78fb08d616c ↗