vendor:
Graphite2
by:
Google Project Zero
6,5
CVSS
MEDIUM
Heap-Buffer-Overflow
119
CWE
Product Name: Graphite2
Affected Version From: Graphite2 2.3.1
Affected Version To: Graphite2 2.3.2
Patch Exists: YES
Related CWE: CVE-2017-7890
CPE: a:sil:graphite2:2.3.1
Metasploit:
https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2017-7890/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2017-7890/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2017-7890/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp1-cve-2017-7890/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2017-7890/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp2-cve-2017-7890/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2017-7890/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2017-7890/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2017-7890/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2017-7890/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2017-7890/, https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2017-7890/, https://www.rapid7.com/db/vulnerabilities/php-cve-2017-7890/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2017
Graphite2 NameTable::getName Method Heap-Buffer-Overflow Vulnerability
Graphite2 is a rendering engine for OpenType fonts which is used by many applications. A heap-buffer-overflow vulnerability was discovered in the Graphite2 NameTable::getName method. This vulnerability can be triggered by running the gr2FontTest utility with the -demand -cache /path/to/file command. This vulnerability can lead to arbitrary code execution.
Mitigation:
No known mitigation is available for this vulnerability.