CVE-2017-8287Improper Restriction of Operations within the Bounds of a Memory Buffer in Freetype

Severity
9.8CRITICALNVD
EPSS
0.8%
top 25.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 27
Latest updateMay 13

Description

FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in psaux/psobjs.c.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

debiandebian/freetype< freetype 2.6.3-3.2 (bookworm)
Debianfreetype/freetype< 2.6.3-3.2+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8m73-wffv-p6q9: FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in psa2022-05-13
OSV
CVE-2017-8287: FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in psa2017-04-27

📋Vendor Advisories

3
Ubuntu
FreeType vulnerabilities2017-05-09
Red Hat
freetype: heap-based buffer overflow related to the t1_builder_close_contour function2017-03-26
Debian
CVE-2017-8287: freetype - FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based b...2017

💬Community

4
Bugzilla
CVE-2017-8287 mingw-freetype: freetype: heap-based buffer overflow related to the t1_builder_close_contour function [fedora-all]2017-04-27
Bugzilla
CVE-2017-8287 freetype: heap-based buffer overflow related to the t1_builder_close_contour function [fedora-all]2017-04-27
Bugzilla
CVE-2017-8287 freetype: heap-based buffer overflow related to the t1_builder_close_contour function2017-04-27
Bugzilla
CVE-2017-8287 mingw-freetype: freetype: heap-based buffer overflow related to the t1_builder_close_contour function [epel-7]2017-04-27