First published: Thu Apr 27 2017(Updated: )
FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in psaux/psobjs.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeType | <=2.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8287 is classified as a high-severity vulnerability due to the potential for exploitation via out-of-bounds write.
To fix CVE-2017-8287, update FreeType to version 2.7.2 or later.
CVE-2017-8287 is caused by a heap-based buffer overflow related to the t1_builder_close_contour function.
FreeType versions prior to 2.7.2 are affected by CVE-2017-8287.
The potential impacts of CVE-2017-8287 include application crashes and the possibility of arbitrary code execution.