Heap-based buffer overflow in FreeType - CVE-2017-8287

 

Heap-based buffer overflow in FreeType - CVE-2017-8287

Published: March 15, 2018


Vulnerability identifier: #VU11095
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-8287
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists in the t1_builder_close_contour function due to heap-based buffer overflow. A remote attacker can trigger out-of-bounds write and execute arbitrary code.

Affected software

FreeType
Arch Linux
Debian Linux
Ubuntu
Slackware Linux
Fedora
freetype (Alpine package)
freetype
Flex System Chassis Management Module (CMM)

How to mitigate CVE-2017-8287

Update to version 2.8.

freetype (Alpine package) - update to 2.5.5-r1
Flex System Chassis Management Module (CMM) - update to 2pet16c-2.5.12c
freetype - addressed in versions 2.6.3-5.fc24, 2.6.5-7.fc25, 2.7.1-6.fc26

External References

Related Security Bulletins