Heap-based buffer overflow in FreeType - CVE-2017-8105
Published: March 15, 2018
Vulnerability identifier: #VU11094
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-8105
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists in the t1_decoder_parse_charstrings function due to heap-based buffer overflow. A remote attacker can trigger out-of-bounds write and execute arbitrary code.
The weakness exists in the t1_decoder_parse_charstrings function due to heap-based buffer overflow. A remote attacker can trigger out-of-bounds write and execute arbitrary code.
Affected software
FreeType
Arch Linux
Debian Linux
Ubuntu
Fedora
freetype (Alpine package)
freetype
Flex System Chassis Management Module (CMM)
Arch Linux
Debian Linux
Ubuntu
Fedora
freetype (Alpine package)
freetype
Flex System Chassis Management Module (CMM)
How to mitigate CVE-2017-8105
Update to version 2.8.
freetype (Alpine package) - update to 2.5.5-r1
Flex System Chassis Management Module (CMM) - update to 2pet16c-2.5.12c
freetype - addressed in versions 2.6.3-5.fc24, 2.6.5-7.fc25, 2.7.1-6.fc26
Flex System Chassis Management Module (CMM) - update to 2pet16c-2.5.12c
freetype - addressed in versions 2.6.3-5.fc24, 2.6.5-7.fc25, 2.7.1-6.fc26
External References
Related Security Bulletins
- Ubuntu update for FreeType
- Ubuntu update for FreeType
- Arch Linux update for lib32-freetype2
- Arch Linux update for freetype2
- Debian update for freetype
- Heap-based buffer overflow in freetype (Alpine package)
- Multiple vulnerabilities in IBM Flex System Chassis Management Module (CMM)
- Fedora 24 update for freetype
- Fedora 25 update for freetype
- Fedora 26 update for freetype