Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-15999

Опубликовано: 19 окт. 2020
Источник: redhat
CVSS3: 8.6
EPSS Критический

Описание

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

A heap buffer overflow leading to out-of-bounds write was found in freetype. Memory allocation based on truncated PNG width and height values allows for an out-of-bounds write to occur in application memory when an attacker supplies a specially crafted TTF file.

Отчет

Although firefox and thunderbird, as shipped with Red Hat Enterprise Linux 6, bundle a version (2.4.11) of freetype in gtk3-private, the version is not affected by this flaw because the vulnerable code was introduced in a subsequent version of freetype. The freetype package shipped with Red Hat Enterprise Linux 5 and 6 is not affected as the vulnerable code was introduced in a subsequent version of freetype. go-freetype as shipped with Red Hat Advanced Cluster Management for Kubernetes is not affected by this flaw because it ships a pure go implementation of freetype which does not include the vulnerable code.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2go-freetypeNot affected
Red Hat Enterprise Linux 5freetypeNot affected
Red Hat Enterprise Linux 6firefoxNot affected
Red Hat Enterprise Linux 6freetypeNot affected
Red Hat Enterprise Linux 6thunderbirdNot affected
Red Hat Enterprise Linux 6 Supplementarychromium-browserFixedRHSA-2020:435126.10.2020
Red Hat Enterprise Linux 7freetypeFixedRHSA-2020:490704.11.2020
Red Hat Enterprise Linux 8freetypeFixedRHSA-2020:495205.11.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsfreetypeFixedRHSA-2020:494905.11.2020
Red Hat Enterprise Linux 8.1 Extended Update SupportfreetypeFixedRHSA-2020:495005.11.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190->CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1890210freetype: Heap-based buffer overflow due to integer truncation in Load_SBit_Png

EPSS

Процентиль: 100%
0.92766
Критический

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
больше 4 лет назад

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 9.6
nvd
больше 4 лет назад

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 6.5
msrc
4 месяца назад

Описание отсутствует

CVSS3: 9.6
debian
больше 4 лет назад

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.1 ...

suse-cvrf
больше 4 лет назад

Security update for freetype2

EPSS

Процентиль: 100%
0.92766
Критический

8.6 High

CVSS3