CVE-2020-15999: Heap buffer overflow in Freetype
Impact A memory corruption bug(Heap overflow) in the FreeType font rendering library.
> This can be exploited by attackers to execute arbitrary code by using specially crafted fonts with embedded PNG images .
As per https://www.secpod.com/blog/chrome-zero-day-under-active-exploitation-patch-now/
Google is aware of reports that an exploit for CVE-2020-15999 exists in the wild.
Patches Upgrade to 85.3.130 or higher
References - https://www.secpod.com/blog/chrome-zero-day-under-active-exploitation-patch-now/ - https://www.zdnet.com/article/google-releases-chrome-security-update-to-patch-actively-exploited-zero-day/ - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15999 - https://magpcss.org/ceforum/viewtopic.php?f=10&t=17942
To review the CEF/Chromium patch see https://bitbucket.org/chromiumembedded/cef/commits/cd6cbe008b127990036945fb75e7c2c1594ab10d
Other sources
Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function LoadSBitPng when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.
— CISA
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
In Freetype, if PNG images were embedded into fonts, the LoadSBitPng function contained an integer overflow that led to a heap buffer overflow, memory corruption, and an exploitable crash.Note: While Project Zero did discover instances of this vulnerability being exploited in the wild against Chrome, in Firefox this vulnerability is only triggerable if a rarely-used, hidden preference is toggled, and only affected Linux and Android operating systems. Other operating systems are unaffected; and Linux and Android are unaffected in the default configuration.
In Freetype, if PNG images were embedded into fonts, the LoadSBitPng function contained an integer overflow that led to a heap buffer overflow, memory corruption, and an exploitable crash.Note: While Project Zero did discover instances of this vulnerability being exploited in the wild against Chrome, in Thunderbird this vulnerability is only triggerable if a rarely-used, hidden preference is toggled, and only affected Linux and Android operating systems. Other operating systems are unaffected; and Linux and Android are unaffected in the default configuration.
— Mozilla
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 90.0.4430.212-1~deb10u1 - Upgrade
Upgrade
debian/freetypeto a version that resolves this vulnerability.Fixed in 2.9.1-3+deb10u3Fixed in 2.9.1-3+deb10u2Fixed in 2.10.4+dfsg-1+deb11u1Fixed in 2.12.1+dfsg-5Fixed in 2.13.2+dfsg-1 - Upgrade
Upgrade
nuget/CefSharp.Wpf.HwndHostto a version that resolves this vulnerability.Fixed in 85.3.130 - Upgrade
Upgrade
nuget/CefSharp.WinFormsto a version that resolves this vulnerability.Fixed in 85.3.130 - Upgrade
Upgrade
nuget/CefSharp.Wpfto a version that resolves this vulnerability.Fixed in 85.3.130 - Upgrade
Upgrade
nuget/CefSharp.Commonto a version that resolves this vulnerability.Fixed in 85.3.130 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 78.5 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 83 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 78.5 - Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 86.0.4240.111 - Upgrade
Upgrade
debian/freetypeto a version that resolves this vulnerability.Fixed in 2.9.1-3+deb10u3 - Upgrade
Upgrade
debian/freetypeto a version that resolves this vulnerability.Fixed in 2.9.1-3+deb10u2 - Upgrade
Upgrade
debian/freetypeto a version that resolves this vulnerability.Fixed in 2.10.4+dfsg-1+deb11u1 - Upgrade
Upgrade
debian/freetypeto a version that resolves this vulnerability.Fixed in 2.12.1+dfsg-5 - Upgrade
Upgrade
debian/freetypeto a version that resolves this vulnerability.Fixed in 2.13.2+dfsg-1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-26951
- CVE-2020-16012
- CVE-2020-26953
- CVE-2020-26956
- CVE-2020-26958
- CVE-2020-26959
- CVE-2020-26960
- CVE-2020-15999
- CVE-2020-26961
- CVE-2020-26965
- CVE-2020-26966
- CVE-2020-26968
- CVE-2020-26952
- CVE-2020-26954
- CVE-2020-26955
- CVE-2020-26957
- CVE-2020-26962
- CVE-2020-26963
- CVE-2020-26964
- CVE-2020-26967
- CVE-2020-26969
- CVE-2020-16000
- CVE-2020-16001
- CVE-2020-16002
- CVE-2020-16003
Frequently Asked Questions
What is CVE-2020-15999?
CVE-2020-15999 is a Heap Buffer Overflow Vulnerability in Google Chrome caused by an integer overflow in the Load_SBit_Png function in Freetype.
How severe is CVE-2020-15999?
CVE-2020-15999 has a severity rating of 6.5 out of 10.
Which software is affected by CVE-2020-15999?
Google Chrome, Mozilla Thunderbird, Mozilla Firefox, Mozilla Firefox ESR, and Google Android are affected by CVE-2020-15999.
How can CVE-2020-15999 be fixed?
To fix CVE-2020-15999, update to the latest version of Google Chrome, Mozilla Thunderbird, Mozilla Firefox, Mozilla Firefox ESR, or Google Android.
Where can I find more information about CVE-2020-15999?
You can find more information about CVE-2020-15999 at the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1672223), [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2020-51/), [Android Source](https://android.googlesource.com/platform/external/freetype/+/358c238408a1fdc357d9afef6811369a7701e004).