CVE-2014-9675
published 2015-02-08CVE-2014-9675: bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to…
PriorityP430medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
4.16%
89.7th percentile
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | freetype | < freetype 2.5.2-3 (bookworm) | freetype 2.5.2-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| freetype | freetype | <= 2.5.3 | — |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| freetype | freetype | >= 0 < 2.5.2-3 | 2.5.2-3 |
| android | — | — | |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_eus | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2014-9675: Android Security Bulletin 2016-11-01
CVE: CVE-2014-9675
Severity: HIGH
Affected AOSP versions: 4
vendor_android·2016-11-01·CVSS 5.0
CVE-2014-9675 [MEDIUM] CVE-2014-9675: Android Security Bulletin 2016-11-01
CVE: CVE-2014-9675
Severity: HIGH
Affected AOSP versions: 4
Android Security Bulletin 2016-11-01
CVE: CVE-2014-9675
Severity: HIGH
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1
References: A-24296662
[2]
Ubuntu
FreeType vulnerabilities
vendor_ubuntu·2015-02-24
CVE-2014-9656 FreeType vulnerabilities
Title: FreeType vulnerabilities
Summary: FreeType could be made to crash or run programs as your login if it opened
a specially crafted file.
Mateusz Jurczyk discovered that FreeType did not correctly handle certain
malformed font files. If a user were tricked into using a specially crafted
font file, a remote attacker could cause FreeType to crash or possibly
execute arbitrary code with user privileges.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Red Hat
freetype: information leak in _bdf_add_property()
vendor_redhat·2015-02-08·CVSS 5.0
CVE-2014-9675 [MEDIUM] CWE-200 freetype: information leak in _bdf_add_property()
freetype: information leak in _bdf_add_property()
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
Package: freetype (Red Hat Enterprise Linux 4) - Will not fix
Package: freetype (Red Hat Enterprise Linux 5) - Will not fix
Package: mingw-virt-viewer (Red Hat Enterprise Virtualization 3) - Affected
Debian
CVE-2014-9675: freetype - bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifyin...
vendor_debian·2014·CVSS 5.0
CVE-2014-9675 [MEDIUM] CVE-2014-9675: freetype - bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifyin...
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
Scope: local
bookworm: resolved (fixed in 2.5.2-3)
bullseye: resolved (fixed in 2.5.2-3)
forky: resolved (fixed in 2.5.2-3)
sid: resolved (fixed in 2.5.2-3)
trixie: resolved (fixed in 2.5.2-3)
GHSA
GHSA-gp42-2rqf-vfq6: bdf/bdflib
ghsa_unreviewed·2022-05-14
CVE-2014-9675 [MEDIUM] GHSA-gp42-2rqf-vfq6: bdf/bdflib
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
OSV
CVE-2014-9675: bdf/bdflib
osv·2015-02-08·CVSS 5.0
CVE-2014-9675 [MEDIUM] CVE-2014-9675: bdf/bdflib
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9675 freetype: information leak in _bdf_add_property()
bugzilla·2015-02-10·CVSS 5.0
CVE-2014-9675 [MEDIUM] CVE-2014-9675 freetype: information leak in _bdf_add_property()
CVE-2014-9675 freetype: information leak in _bdf_add_property()
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
Upstream issue:
http://code.google.com/p/google-security-research/issues/detail?id=151
Upstream patch:
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=2c4832d30939b45c05757f0a05128ce64c4cacc7
Discussion:
Created freetype tracking bugs for this issue:
Affects: fedora-all [bug 1191193]
---
freetype-2.5.3-15.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report.
---
freetype-2.5.0-9.fc2
Bugzilla
CVE-2014-9675 freetype: bypass the ASLR protection mechanism via a crafted BDF font [fedora-all]
bugzilla·2015-02-10·CVSS 5.0
CVE-2014-9675 [MEDIUM] CVE-2014-9675 freetype: bypass the ASLR protection mechanism via a crafted BDF font [fedora-all]
CVE-2014-9675 freetype: bypass the ASLR protection mechanism via a crafted BDF font [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple sup
http://advisories.mageia.org/MGASA-2015-0083.htmlhttp://code.google.com/p/google-security-research/issues/detail?id=151http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=2c4832d30939b45c05757f0a05128ce64c4cacc7http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150148.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-February/150162.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00091.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0696.htmlhttp://www.debian.org/security/2015/dsa-3188http://www.mandriva.com/security/advisories?name=MDVSA-2015:055http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/72986http://www.ubuntu.com/usn/USN-2510-1http://www.ubuntu.com/usn/USN-2739-1https://security.gentoo.org/glsa/201503-05https://source.android.com/security/bulletin/2016-11-01.htmlhttp://advisories.mageia.org/MGASA-2015-0083.htmlhttp://code.google.com/p/google-security-research/issues/detail?id=151http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=2c4832d30939b45c05757f0a05128ce64c4cacc7http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150148.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-February/150162.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00091.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0696.htmlhttp://www.debian.org/security/2015/dsa-3188http://www.mandriva.com/security/advisories?name=MDVSA-2015:055http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/72986http://www.ubuntu.com/usn/USN-2510-1http://www.ubuntu.com/usn/USN-2739-1https://security.gentoo.org/glsa/201503-05https://source.android.com/security/bulletin/2016-11-01.html
2015-02-08
Published