Уязвимость переполнения буфера в куче в Freetype в Google Chrome через специально созданную HTML-страницу
Описание
Уязвимость переполнения буфера в куче в библиотеке Freetype, используемой в Google Chrome, позволяет злоумышленнику удаленно эксплуатировать повреждение памяти через специально созданную HTML-страницу.
Затронутые версии ПО
- Google Chrome версии до 86.0.4240.111
Тип уязвимости
Переполнение буфера в куче
Ссылки
- Broken LinkMailing ListThird Party Advisory
- Mailing ListNot ApplicableThird Party Advisory
- Third Party Advisory
- ExploitIssue TrackingThird Party Advisory
- ExploitThird Party Advisory
- Release Notes
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
- Broken LinkMailing ListThird Party Advisory
- Mailing ListNot ApplicableThird Party Advisory
- Third Party Advisory
- ExploitIssue TrackingThird Party Advisory
- ExploitThird Party Advisory
- Release Notes
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
EPSS
9.6 Critical
CVSS3
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.1 ...
EPSS
9.6 Critical
CVSS3
4.3 Medium
CVSS2