cbcvebase.
CVE-2014-9675
published 2015-02-08

CVE-2014-9675: bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to…

medium5CVSS 3.1
AVNACLAuNCPINAN
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianfreetype< freetype 2.5.2-3 (bookworm)freetype 2.5.2-3 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
freetypefreetype<= 2.5.3
freetypefreetype>= 0 < 2.5.2-32.5.2-3
freetypefreetype>= 0 < 2.5.2-32.5.2-3
freetypefreetype>= 0 < 2.5.2-32.5.2-3
freetypefreetype>= 0 < 2.5.2-32.5.2-3
googleandroid
opensuseopensuse
opensuseopensuse
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_hpc_node
redhatenterprise_linux_hpc_node
redhatenterprise_linux_hpc_node_eus
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_eus

CVSS provenance

nvd5.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM