CVE-2014-9675
EPSS 1.4%發布日:2015/2/8修改日:2026/4/28
也稱為:DEBIAN-CVE-2014-9675
描述
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
受影響套件(1)
- Debian/freetypefrom 0, < 2.5.2-3