Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-9675

Опубликовано: 08 фев. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5

Описание

bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.

РелизСтатусПримечание
devel

released

2.5.2-2ubuntu3
esm-infra-legacy/trusty

released

2.5.2-1ubuntu2.4
lucid

released

2.3.11-1ubuntu2.8
precise

released

2.4.8-1ubuntu2.2
trusty

released

2.5.2-1ubuntu2.4
trusty/esm

released

2.5.2-1ubuntu2.4
upstream

released

2.5.4
utopic

released

2.5.2-2ubuntu1.1

Показывать по

EPSS

Процентиль: 84%
0.02335
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
больше 10 лет назад

bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.

nvd
больше 10 лет назад

bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.

debian
больше 10 лет назад

bdf/bdflib.c in FreeType before 2.5.4 identifies property names by onl ...

github
больше 3 лет назад

bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.

oracle-oval
больше 10 лет назад

ELSA-2015-0696: freetype security update (IMPORTANT)

EPSS

Процентиль: 84%
0.02335
Низкий

5 Medium

CVSS2