VulnerabilityModified
CVE-2014-9675
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
MEDIUM 5.0EPSS 4.16%
Does this matter?
Lower severity and a low EPSS score (4.16%). Track it; it rarely justifies an emergency change on its own.
Description
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 4.16% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- canonical/ubuntu linux · freetype/freetype · debian/debian linux · fedoraproject/fedora · redhat/enterprise linux desktop · redhat/enterprise linux hpc node · redhat/enterprise linux hpc node eus · redhat/enterprise linux server · redhat/enterprise linux server eus · redhat/enterprise linux workstation · opensuse/opensuse
- Source
- cve@mitre.org
References
- http://advisories.mageia.org/MGASA-2015-0083.htmlThird Party Advisory
- http://code.google.com/p/google-security-research/issues/detail?id=151Exploit
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=2c4832d30939b45c05757f0a05128ce64c4cacc7Issue Tracking
- http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150148.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150162.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-03/msg00091.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0696.htmlThird Party Advisory
- http://www.debian.org/security/2015/dsa-3188Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:055Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlThird Party Advisory
- http://www.securityfocus.com/bid/72986
- http://www.ubuntu.com/usn/USN-2510-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2739-1Third Party Advisory
- https://security.gentoo.org/glsa/201503-05
- https://source.android.com/security/bulletin/2016-11-01.html
- http://advisories.mageia.org/MGASA-2015-0083.htmlThird Party Advisory
- http://code.google.com/p/google-security-research/issues/detail?id=151Exploit
- http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=2c4832d30939b45c05757f0a05128ce64c4cacc7Issue Tracking
- http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150148.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150162.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-03/msg00091.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0696.htmlThird Party Advisory
- http://www.debian.org/security/2015/dsa-3188Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:055Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlThird Party Advisory
- http://www.securityfocus.com/bid/72986
- http://www.ubuntu.com/usn/USN-2510-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2739-1Third Party Advisory
- https://security.gentoo.org/glsa/201503-05
- https://source.android.com/security/bulletin/2016-11-01.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.