Denial of Service Vulnerability in FreeType Software
CVE-2014-9747
7.5HIGH
What is CVE-2014-9747?
The t42_parse_encoding function in FreeType versions prior to 2.5.4 exhibits a flaw in the handling of immediates-only mode. This weakness can be exploited by remote attackers to trigger an infinite loop, resulting in a denial of service. The vulnerability is specifically related to the processing of Type42 fonts, making it a potential target for attackers seeking to disrupt services or systems utilizing this software. To mitigate this risk, users are advised to upgrade to patched versions of the FreeType software.