CVE-2017-8105Out-of-bounds Write in Freetype

Severity
9.8CRITICALNVD
EPSS
1.6%
top 18.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 24
Latest updateMay 13

Description

FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

debiandebian/freetype< freetype 2.6.3-3.2 (bookworm)
NVDfreetype/freetype< 2.7.1
Debianfreetype/freetype< 2.6.3-3.2+3

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3f3f-jhpf-w85x: FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in2022-05-13
OSV
CVE-2017-8105: FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in2017-04-24

📋Vendor Advisories

3
Ubuntu
FreeType vulnerabilities2017-05-09
Red Hat
freetype: heap-based buffer overflow related to the t1_decoder_parse_charstrings2017-03-24
Debian
CVE-2017-8105: freetype - FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based b...2017

💬Community

4
Bugzilla
CVE-2017-8105 freetype: heap-based buffer overflow related to the t1_decoder_parse_charstrings [fedora-all]2017-04-28
Bugzilla
CVE-2017-8105 mingw-freetype: freetype: heap-based buffer overflow related to the t1_decoder_parse_charstrings [fedora-all]2017-04-28
Bugzilla
CVE-2017-8105 freetype: heap-based buffer overflow related to the t1_decoder_parse_charstrings2017-04-28
Bugzilla
CVE-2017-8105 mingw-freetype: freetype: heap-based buffer overflow related to the t1_decoder_parse_charstrings [epel-7]2017-04-28
CVE-2017-8105 — Out-of-bounds Write in Freetype | cvebase