CVE-2014-9675
EPSS 1.4%
Description
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
How to fix CVE-2014-9675
To remediate CVE-2014-9675, upgrade the affected package to a fixed version below.
- Debian/freetype—upgrade to 2.5.2-3 or later
Is CVE-2014-9675 being exploited?
Low — EPSS is 1.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.5.2-3