CVE-2014-9675
Publication date 8 February 2015
Last updated 24 July 2024
Ubuntu priority
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
Status
Package | Ubuntu Release | Status |
---|---|---|
freetype | ||
14.04 LTS trusty |
Fixed 2.5.2-1ubuntu2.4
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2510-1
- FreeType vulnerabilities
- 24 February 2015