CVE-2017-8287: Buffer Overflow
Published Apr 27, 2017
·Updated
FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1builderclosecontour function in psaux/psobjs.c.
Affected Software
1 affected component
FreeType<=2.7.1
Remediation
Event History
Apr 27, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8287?
CVE-2017-8287 is classified as a high-severity vulnerability due to the potential for exploitation via out-of-bounds write.
2
How do I fix CVE-2017-8287?
To fix CVE-2017-8287, update FreeType to version 2.7.2 or later.
3
What causes CVE-2017-8287?
CVE-2017-8287 is caused by a heap-based buffer overflow related to the t1_builder_close_contour function.
4
Which versions of FreeType are affected by CVE-2017-8287?
FreeType versions prior to 2.7.2 are affected by CVE-2017-8287.
5
What are the potential impacts of CVE-2017-8287?
The potential impacts of CVE-2017-8287 include application crashes and the possibility of arbitrary code execution.