Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-8105

Опубликовано: 24 апр. 2017
Источник: debian
EPSS Низкий

Описание

FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
freetypefixed2.6.3-3.2package

Примечания

  • Fixed by: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=f958c48ee431bef8d4d466b40c9cb2d4dbcb7791

  • https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=935

EPSS

Процентиль: 76%
0.00966
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.

CVSS3: 7
redhat
почти 9 лет назад

FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.

CVSS3: 9.8
nvd
почти 9 лет назад

FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.

CVSS3: 9.8
github
больше 3 лет назад

FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.

fstec
почти 9 лет назад

Уязвимость функции t1_decoder_parse_charstrings библиотеки FreeType, позволяющая нарушителю выполнить запись данных за границами буфера

EPSS

Процентиль: 76%
0.00966
Низкий