CVE-2014-9675: Canonical Ubuntu Linux

Medium severity, CVSS 5.0. EPSS: 4.2% chance of exploitation in the next 30 days.

bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 14.04 only; version 14.10 only; version 15.04 only
  • Debian Debian Linux: version 7.0 only
  • Fedoraproject Fedora: version 20 only; version 21 only
  • FreeType FreeType: up to and including 2.5.3
  • Opensuse Opensuse: version 13.1 only; version 13.2 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Hpc Node: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Hpc Node Eus: version 7.1 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Eus: version 6.6.z only; version 7.1 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only

Published 2015-02-08. Last modified 2026-06-17.