USN-2510-1
Dashboard / Vulnerabilities / USN-2510-1
USN-2510-1
Summary: freetype vulnerabilities
Details: Mateusz Jurczyk discovered that FreeType did not correctly handle certain malformed font files. If a user were tricked into using a specially crafted font file, a remote attacker could cause FreeType to crash or possibly execute arbitrary code with user privileges.
References: https://ubuntu.com/security/notices/USN-2510-1, https://ubuntu.com/security/CVE-2014-9656, https://ubuntu.com/security/CVE-2014-9657, https://ubuntu.com/security/CVE-2014-9658, https://ubuntu.com/security/CVE-2014-9659, https://ubuntu.com/security/CVE-2014-9660, https://ubuntu.com/security/CVE-2014-9661, https://ubuntu.com/security/CVE-2014-9662, https://ubuntu.com/security/CVE-2014-9663, https://ubuntu.com/security/CVE-2014-9664, https://ubuntu.com/security/CVE-2014-9665, https://ubuntu.com/security/CVE-2014-9666, https://ubuntu.com/security/CVE-2014-9667, https://ubuntu.com/security/CVE-2014-9668, https://ubuntu.com/security/CVE-2014-9669, https://ubuntu.com/security/CVE-2014-9670, https://ubuntu.com/security/CVE-2014-9671, https://ubuntu.com/security/CVE-2014-9672, https://ubuntu.com/security/CVE-2014-9673, https://ubuntu.com/security/CVE-2014-9674, https://ubuntu.com/security/CVE-2014-9675
Affected packages
Package
Name: freetype
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
