bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
2015-02-08T11:59:36.490
2025-04-12T10:46:40.837
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | canonical | ubuntu_linux | 10.04 | Yes |
Operating System | canonical | ubuntu_linux | 12.04 | Yes |
Operating System | canonical | ubuntu_linux | 14.04 | Yes |
Operating System | canonical | ubuntu_linux | 14.10 | Yes |
Operating System | canonical | ubuntu_linux | 15.04 | Yes |
Application | freetype | freetype | ≤ 2.5.3 | Yes |
Operating System | debian | debian_linux | 7.0 | Yes |
Operating System | fedoraproject | fedora | 20 | Yes |
Operating System | fedoraproject | fedora | 21 | Yes |
Operating System | redhat | enterprise_linux_desktop | 6.0 | Yes |
Operating System | redhat | enterprise_linux_desktop | 7.0 | Yes |
Operating System | redhat | enterprise_linux_hpc_node | 6.0 | Yes |
Operating System | redhat | enterprise_linux_hpc_node | 7.0 | Yes |
Operating System | redhat | enterprise_linux_hpc_node_eus | 7.1 | Yes |
Operating System | redhat | enterprise_linux_server | 6.0 | Yes |
Operating System | redhat | enterprise_linux_server | 7.0 | Yes |
Operating System | redhat | enterprise_linux_server_eus | 6.6.z | Yes |
Operating System | redhat | enterprise_linux_server_eus | 7.1 | Yes |
Operating System | redhat | enterprise_linux_workstation | 6.0 | Yes |
Operating System | redhat | enterprise_linux_workstation | 7.0 | Yes |
Operating System | opensuse | opensuse | 13.1 | Yes |
Operating System | opensuse | opensuse | 13.2 | Yes |