First published: Fri Apr 14 2017(Updated: )
FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Freetype Freetype | <=2.7 | |
Oracle Outside In Technology | =8.5.4 | |
<=6.0.2 | ||
<=6.0.6.1 | ||
<=6.0.6 | ||
<=7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this FreeType 2 vulnerability is CVE-2016-10328.
The severity of CVE-2016-10328 is critical with a severity value of 9.8.
The software affected by CVE-2016-10328 includes FreeType, Oracle Outside In Technology, IBM RDNG, and IBM DOORS Next.
CVE-2016-10328 is exploited by sending a specially crafted request to trigger a heap-based buffer overflow.
Yes, for more information on CVE-2016-10328, you can refer to the following links: [link1], [link2], [link3].