CVE-2014-9675
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present,
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
MEDIUM · CVSS 5
EPSS 0.0141
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0