Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-7858

Опубликовано: 14 апр. 2017
Источник: debian
EPSS Низкий

Описание

FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
freetypenot-affectedpackage

Примечания

  • Introduced after: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=813aca51d28704f7ffc470721167738fa8decb3d

  • Fixed by: https://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=779309744222a736eba0f1731e8162fce6288d4e

  • https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=738

EPSS

Процентиль: 85%
0.02409
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.

CVSS3: 7.8
redhat
почти 9 лет назад

FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.

CVSS3: 9.8
nvd
почти 9 лет назад

FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.

CVSS3: 9.8
github
больше 3 лет назад

FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.

EPSS

Процентиль: 85%
0.02409
Низкий