Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-8105

Опубликовано: 24 мар. 2017
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.

Отчет

Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5freetypeNot affected
Red Hat Enterprise Linux 6freetypeNot affected
Red Hat Enterprise Linux 7freetypeWill not fix
Red Hat Enterprise Virtualization 3mingw-virt-viewerUnder investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1446500freetype: heap-based buffer overflow related to the t1_decoder_parse_charstrings

EPSS

Процентиль: 76%
0.00966
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.

CVSS3: 9.8
nvd
почти 9 лет назад

FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.

CVSS3: 9.8
debian
почти 9 лет назад

FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a he ...

CVSS3: 9.8
github
больше 3 лет назад

FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.

fstec
почти 9 лет назад

Уязвимость функции t1_decoder_parse_charstrings библиотеки FreeType, позволяющая нарушителю выполнить запись данных за границами буфера

EPSS

Процентиль: 76%
0.00966
Низкий

7 High

CVSS3