CVE-2020-15999: Heap buffer overflow in Freetype

Published Oct 19, 2020
·
Updated

Impact A memory corruption bug(Heap overflow) in the FreeType font rendering library.

> This can be exploited by attackers to execute arbitrary code by using specially crafted fonts with embedded PNG images .

As per https://www.secpod.com/blog/chrome-zero-day-under-active-exploitation-patch-now/

Google is aware of reports that an exploit for CVE-2020-15999 exists in the wild.

Patches Upgrade to 85.3.130 or higher

References - https://www.secpod.com/blog/chrome-zero-day-under-active-exploitation-patch-now/ - https://www.zdnet.com/article/google-releases-chrome-security-update-to-patch-actively-exploited-zero-day/ - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15999 - https://magpcss.org/ceforum/viewtopic.php?f=10&t=17942

To review the CEF/Chromium patch see https://bitbucket.org/chromiumembedded/cef/commits/cd6cbe008b127990036945fb75e7c2c1594ab10d

Other sources

Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function LoadSBitPng when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.

CISA

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

In Freetype, if PNG images were embedded into fonts, the LoadSBitPng function contained an integer overflow that led to a heap buffer overflow, memory corruption, and an exploitable crash.Note: While Project Zero did discover instances of this vulnerability being exploited in the wild against Chrome, in Firefox this vulnerability is only triggerable if a rarely-used, hidden preference is toggled, and only affected Linux and Android operating systems. Other operating systems are unaffected; and Linux and Android are unaffected in the default configuration.

In Freetype, if PNG images were embedded into fonts, the LoadSBitPng function contained an integer overflow that led to a heap buffer overflow, memory corruption, and an exploitable crash.Note: While Project Zero did discover instances of this vulnerability being exploited in the wild against Chrome, in Thunderbird this vulnerability is only triggerable if a rarely-used, hidden preference is toggled, and only affected Linux and Android operating systems. Other operating systems are unaffected; and Linux and Android are unaffected in the default configuration.

Mozilla

Credit

Sergei Glazunov(Google Project Zero)

Affected Software

18 affected componentsFixes available
debian/chromium
90.0.4430.212-1~deb10u1
debian/freetype
2.9.1-3+deb10u32.9.1-3+deb10u22.10.4+dfsg-1+deb11u12.12.1+dfsg-52.13.2+dfsg-1
nuget/CefSharp.Wpf.HwndHost<85.3.130
85.3.130
nuget/CefSharp.WinForms<85.3.130
85.3.130
nuget/CefSharp.Wpf<85.3.130
85.3.130
nuget/CefSharp.Common<85.3.130
85.3.130
Google Chrome FreeType
Google Android
Mozilla Thunderbird<78.5
78.5
Mozilla Firefox<83
83
Mozilla Firefox ESR<78.5
78.5
Google Chrome<86.0.4240.111
86.0.4240.111
Google Chrome<86.0.4240.111
FreeType FreeType>=2.6.0<2.10.4
Debian Debian Linux=10.0
Fedoraproject Fedora=31
openSUSE Backports SLE=15.0-sp2
NetApp ONTAP Select Deploy administration utility

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/chromium to a version that resolves this vulnerability.

    Fixed in 90.0.4430.212-1~deb10u1
  2. Upgrade

    Upgrade debian/freetype to a version that resolves this vulnerability.

    Fixed in 2.9.1-3+deb10u3Fixed in 2.9.1-3+deb10u2Fixed in 2.10.4+dfsg-1+deb11u1Fixed in 2.12.1+dfsg-5Fixed in 2.13.2+dfsg-1
  3. Upgrade

    Upgrade nuget/CefSharp.Wpf.HwndHost to a version that resolves this vulnerability.

    Fixed in 85.3.130
  4. Upgrade

    Upgrade nuget/CefSharp.WinForms to a version that resolves this vulnerability.

    Fixed in 85.3.130
  5. Upgrade

    Upgrade nuget/CefSharp.Wpf to a version that resolves this vulnerability.

    Fixed in 85.3.130
  6. Upgrade

    Upgrade nuget/CefSharp.Common to a version that resolves this vulnerability.

    Fixed in 85.3.130
  7. Upgrade

    Upgrade Thunderbird to a version that resolves this vulnerability.

    Fixed in 78.5
  8. Upgrade

    Upgrade Firefox to a version that resolves this vulnerability.

    Fixed in 83
  9. Upgrade

    Upgrade Firefox ESR to a version that resolves this vulnerability.

    Fixed in 78.5
  10. Upgrade

    Upgrade Google Chrome (Trace Event) to a version that resolves this vulnerability.

    Fixed in 86.0.4240.111
  11. Upgrade

    Upgrade debian/freetype to a version that resolves this vulnerability.

    Fixed in 2.9.1-3+deb10u3
  12. Upgrade

    Upgrade debian/freetype to a version that resolves this vulnerability.

    Fixed in 2.9.1-3+deb10u2
  13. Upgrade

    Upgrade debian/freetype to a version that resolves this vulnerability.

    Fixed in 2.10.4+dfsg-1+deb11u1
  14. Upgrade

    Upgrade debian/freetype to a version that resolves this vulnerability.

    Fixed in 2.12.1+dfsg-5
  15. Upgrade

    Upgrade debian/freetype to a version that resolves this vulnerability.

    Fixed in 2.13.2+dfsg-1

Event History

Oct 19, 2020
CVE Published
12:00 AM
Known Exploited
12:00 AM
Oct 27, 2020
Advisory Published
via GitHub·07:47 PM
Data Sourced
via GitHub·07:47 PM
DescriptionSeverityWeaknessAffected Software
Nov 3, 2020
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Jan 4, 2021
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2020-15999?

CVE-2020-15999 is a Heap Buffer Overflow Vulnerability in Google Chrome caused by an integer overflow in the Load_SBit_Png function in Freetype.

2

How severe is CVE-2020-15999?

CVE-2020-15999 has a severity rating of 6.5 out of 10.

3

Which software is affected by CVE-2020-15999?

Google Chrome, Mozilla Thunderbird, Mozilla Firefox, Mozilla Firefox ESR, and Google Android are affected by CVE-2020-15999.

4

How can CVE-2020-15999 be fixed?

To fix CVE-2020-15999, update to the latest version of Google Chrome, Mozilla Thunderbird, Mozilla Firefox, Mozilla Firefox ESR, or Google Android.

5

Where can I find more information about CVE-2020-15999?

You can find more information about CVE-2020-15999 at the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1672223), [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2020-51/), [Android Source](https://android.googlesource.com/platform/external/freetype/+/358c238408a1fdc357d9afef6811369a7701e004).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203