参照: Official debian advisory, NVD, CVE.org · CVE 詳細
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2014-9675 not yet assigned priority: Debian including 1 source packages (freetype), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5.
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.