CVE-2016-10328
published 2017-04-14CVE-2016-10328: FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c.
PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.70%
88.5th percentile
FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freetype | — | — |
| freetype | freetype | <= 2.7 | — |
| freetype | freetype | >= 0 < 2.5.2-1ubuntu2.7 | 2.5.2-1ubuntu2.7 |
| freetype | freetype | >= 0 < 2.6.1-0.1ubuntu2.2 | 2.6.1-0.1ubuntu2.2 |
| oracle | outside_in_technology | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Installation (FreeType) — CVE-2016-10328
vendor_oracle·2020-04-15·CVSS 9.8
CVE-2016-10328 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Installation (FreeType) — CVE-2016-10328
Oracle Oracle Fusion Middleware Risk Matrix: Installation (FreeType) vulnerability
CVE: CVE-2016-10328
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Ubuntu
FreeType vulnerability
vendor_ubuntu·2017-04-21
CVE-2016-10328 FreeType vulnerability
Title: FreeType vulnerability
Summary: FreeType could be made to crash or run programs if it opened a specially
crafted font file.
It was discovered that a heap-based buffer overflow existed in the
FreeType library. If a user were tricked into using a specially
crafted font file, a remote attacker could cause FreeType to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Red Hat
freetype: heap-based buffer overflow related to the cff_parser_run function
vendor_redhat·2016-12-23·CVSS 9.8
CVE-2016-10328 [CRITICAL] CWE-122 freetype: heap-based buffer overflow related to the cff_parser_run function
freetype: heap-based buffer overflow related to the cff_parser_run function
FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c.
Package: freetype (Red Hat Enterprise Linux 5) - Not affected
Package: freetype (Red Hat Enterprise Linux 6) - Not affected
Package: freetype (Red Hat Enterprise Linux 7) - Not affected
Package: mingw-virt-viewer (Red Hat Enterprise Virtualization 3) - Not affected
Debian
CVE-2016-10328: freetype - FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based b...
vendor_debian·2016·CVSS 9.8
CVE-2016-10328 [CRITICAL] CVE-2016-10328: freetype - FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based b...
FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-48h9-2rjq-qf7x: FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse
ghsa_unreviewed·2022-05-13
CVE-2016-10328 [CRITICAL] CWE-787 GHSA-48h9-2rjq-qf7x: FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse
FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c.
OSV
CVE-2016-10328: FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse
osv·2017-04-14·CVSS 9.8
CVE-2016-10328 [CRITICAL] CVE-2016-10328: FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse
FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-10328 freetype: heap-based buffer overflow related to the cff_parser_run function
bugzilla·2017-04-24·CVSS 9.8
CVE-2016-10328 [CRITICAL] CVE-2016-10328 freetype: heap-based buffer overflow related to the cff_parser_run function
CVE-2016-10328 freetype: heap-based buffer overflow related to the cff_parser_run function
FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c.
Bug report:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=289
Discussion:
Created freetype tracking bugs for this issue:
Affects: fedora-all [bug 1444917]
Created mingw-freetype tracking bugs for this issue:
Affects: epel-7 [bug 1444915]
Affects: fedora-all [bug 1444916]
---
I can not reproduce this one too with our freetype versions.
---
This issue arises due to the following commit:
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=3bd79cc257499f1850a1bace21f3ae371e3b40f0
Which has not been backported to vers
Bugzilla
CVE-2016-10328 CVE-2017-7857 CVE-2017-7858 CVE-2017-7864 freetype: various flaws [fedora-all]
bugzilla·2017-04-24·CVSS 9.8
CVE-2016-10328 [CRITICAL] CVE-2016-10328 CVE-2017-7857 CVE-2017-7858 CVE-2017-7864 freetype: various flaws [fedora-all]
CVE-2016-10328 CVE-2017-7857 CVE-2017-7858 CVE-2017-7864 freetype: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2016-10328 CVE-2017-7857 CVE-2017-7858 CVE-2017-7864 mingw-freetype: various flaws [epel-7]
bugzilla·2017-04-24·CVSS 9.8
CVE-2016-10328 [CRITICAL] CVE-2016-10328 CVE-2017-7857 CVE-2017-7858 CVE-2017-7864 mingw-freetype: various flaws [epel-7]
CVE-2016-10328 CVE-2017-7857 CVE-2017-7858 CVE-2017-7864 mingw-freetype: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following templat
Bugzilla
CVE-2016-10328 CVE-2017-7857 CVE-2017-7858 CVE-2017-7864 mingw-freetype: various flaws [fedora-all]
bugzilla·2017-04-24·CVSS 9.8
CVE-2016-10328 [CRITICAL] CVE-2016-10328 CVE-2017-7857 CVE-2017-7858 CVE-2017-7864 mingw-freetype: various flaws [fedora-all]
CVE-2016-10328 CVE-2017-7857 CVE-2017-7858 CVE-2017-7864 mingw-freetype: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=beecf80a6deecbaf5d264d4f864451bde4fe98b8http://savannah.nongnu.org/bugs/?func=detailitem&item_id=49858http://www.securityfocus.com/bid/97677https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=289https://security.gentoo.org/glsa/201706-14https://www.oracle.com/security-alerts/cpuapr2020.htmlhttp://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=beecf80a6deecbaf5d264d4f864451bde4fe98b8http://savannah.nongnu.org/bugs/?func=detailitem&item_id=49858http://www.securityfocus.com/bid/97677https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=289https://security.gentoo.org/glsa/201706-14https://www.oracle.com/security-alerts/cpuapr2020.html
2017-04-14
Published