PT-2015-4348 · Freetype+5 · Freetype+5

Mateusz Jurczyk

·

Publicado

2014-12-07

·

Atualizado

2024-06-15

·

CVE-2014-9675

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions FreeType versions prior to 2.5.4
Description The issue allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font. This is due to the way property names are identified in the bdf/bdflib.c file, which only verifies that an initial substring is present.
Recommendations For versions prior to 2.5.4, update to version 2.5.4 or later to resolve the issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2420
CESA-2015_0696
CVE-2014-9675
DLA-185-1
DSA-3188-1
MGASA-2015-0083
OPENSUSE-SU-2024:10172-1
OPENSUSE-SU-2024:10438-1
RHSA-2015:0696
RHSA-2015_0696
SUSE-SU-2015:0455-1
SUSE-SU-2015:0463-1
USN-2510-1

Produtos afetados

Alt Linux
Centos
Freetype
Red Hat
Suse
Ubuntu