VDB

DEBIAN-CVE-2014-9675

DEBIAN-CVE-2014-9675 PUBLISHED

bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.

Affected Products

VendorProductVersions
Debian:14freetype0, 0, 0
Debian:11freetype0, 0, 0
Debian:13freetype0, 0, 0
Debian:12freetype0, 0, 0

Timeline

  • Feb 8, 2015 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›