bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-185-1 | freetype security update |
Debian DSA |
DSA-3188-1 | freetype security update |
EUVD |
EUVD-2014-9485 | bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font. |
Ubuntu USN |
USN-2510-1 | FreeType vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T13:55:04.532Z
Reserved: 2015-02-07T00:00:00
Link: CVE-2014-9675
No data.
Status : Deferred
Published: 2015-02-08T11:59:36.490
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-9675
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN