CVE-2014-2241: Canonical Ubuntu Linux

Medium severity, CVSS 6.8. EPSS: 1.9% chance of exploitation in the next 30 days.

The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a subroutine exists, which allows remote attackers to cause a denial of service (assertion failure), as demonstrated by a crafted ttf file.

Affected products

  • Canonical Ubuntu Linux: version 13.10 only
  • FreeType FreeType: up to and including 2.5.2; version 2.5 only; version 2.5.1 only

Published 2014-03-18. Last modified 2026-06-17.