bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
Find out more about CVE-2014-9675 from the MITRE-CVE dictionary and NIST NVD
Login may be required to access defects or downloads.
Product Name | Status | Defect | Fixed | Downloads |
---|---|---|---|---|
Linux | ||||
Wind River Linux LTS 17 | Not Vulnerable | -- | -- |
Wind River VxWorks Security Alert CVE-2014-9675 for FreeType 2 |
Wind River Linux 8 | Fixed | -- | 8.0.0.0 | -- |
Wind River Linux 9 | Not Vulnerable | -- | -- | -- |
Wind River Linux 7 | Fixed | -- | 7.0.0.4 | -- |
Wind River Linux LTS 21 | Not Vulnerable | -- | -- | -- |
Wind River Linux LTS 22 | Not Vulnerable | -- | -- | -- |
Wind River Linux LTS 18 | Not Vulnerable | -- | -- |
Wind River VxWorks Security Alert CVE-2014-9675 for FreeType 2 |
Wind River Linux LTS 19 | Not Vulnerable | -- | -- |
Wind River VxWorks Security Alert CVE-2014-9675 for FreeType 2 |
Wind River Linux CD release | Not Vulnerable | -- | -- |
Wind River VxWorks Security Alert CVE-2014-9675 for FreeType 2 |
Wind River Linux 6 | Fixed | -- | 6.0.0.19 | -- |
Wind River Linux LTS 23 | Not Vulnerable | -- | -- | -- |
Wind River Linux LTS 24 | Not Vulnerable | -- | -- | -- |
VxWorks | ||||
VxWorks 7 | Fixed | -- | SR0640 |
Wind River VxWorks Security Alert CVE-2014-9675 for FreeType 2 |
VxWorks 6.9 | Won't Fix | -- | -- |
Wind River VxWorks Security Alert CVE-2014-9675 for FreeType 2 |
Helix Virtualization Platform Cert Edition | ||||
Helix Virtualization Platform Cert Edition | Not Vulnerable | -- | -- | -- |
eLxr | ||||
eLxr 12 | Not Vulnerable | -- | -- | -- |
Wind River Studio Cloud Platform |
Product Name | Status | Defect | Fixed | Downloads |
---|