CVE-2014-9675: Medium severity Google Android vulnerability
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9675?
CVE-2014-9675 is considered a high severity vulnerability due to its potential to allow remote attackers to bypass ASLR and exploit heap memory.
How do I fix CVE-2014-9675?
To fix CVE-2014-9675, users should upgrade FreeType to version 2.5.4 or later, or apply relevant patches provided by their operating system vendor.
What systems are affected by CVE-2014-9675?
CVE-2014-9675 affects multiple systems including various versions of FreeType and operating systems like Ubuntu, Debian, Fedora, and Red Hat Enterprise Linux.
Can CVE-2014-9675 be exploited remotely?
Yes, CVE-2014-9675 can be exploited remotely by attackers using specially crafted BDF fonts.
What impact does CVE-2014-9675 have on security?
CVE-2014-9675 could allow attackers to discover heap pointer values, leading to potential arbitrary code execution and compromise of application security.