Skip to content

Heap overflow in the freetype library (CVE-2020-15999)

Critical
amaitland published GHSA-pv36-h7jh-qm62 Oct 25, 2020

Package

nuget CefSharp.Common, CefSharp.Wpf, CefSharp.WinForms, CefSharp.Wpf, CefSharp.Wpf.HwndHost (Nuget)

Affected versions

<= 85.3.121

Patched versions

85.3.130

Description

Impact

A memory corruption bug(Heap overflow) in the FreeType font rendering library.

This can be exploited by attackers to execute arbitrary code by using specially crafted fonts with embedded PNG images .

As per https://www.secpod.com/blog/chrome-zero-day-under-active-exploitation-patch-now/

Google is aware of reports that an exploit for CVE-2020-15999 exists in the wild.

Patches

Upgrade to 85.3.130 or higher

References

To review the CEF/Chromium patch see https://bitbucket.org/chromiumembedded/cef/commits/cd6cbe008b127990036945fb75e7c2c1594ab10d

Severity

Critical

CVE ID

CVE-2020-15999

Weaknesses

No CWEs