First published: Fri Apr 14 2017(Updated: )
FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in truetype/ttobjs.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeType | <=2.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7864 is classified as a high-severity vulnerability due to its potential to cause a heap-based buffer overflow leading to out-of-bounds write.
To mitigate CVE-2017-7864, upgrade FreeType to version 2.7.2 or later, which addresses the out-of-bounds write issue.
CVE-2017-7864 affects FreeType versions up to 2.7.1, prior to the fix implemented in version 2.7.2.
CVE-2017-7864 is caused by a heap-based buffer overflow within the tt_size_reset function, leading to an out-of-bounds write.
Yes, CVE-2017-7864 has the potential to enable remote code execution if exploited, due to the out-of-bounds write vulnerability.