CVE-2014-9675

Source
https://cve.org/CVERecord?id=CVE-2014-9675
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2014-9675.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2014-9675
Downstream
Related
Withdrawn
2026-01-27T04:13:35.624079Z
Published
2015-02-08T11:59:36Z
Modified
2026-01-27T04:13:35.624079Z
Summary
[none]
Details

bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.

References

Affected packages