Loading HuntDB...

Google Chrome FreeType Heap Buffer Overflow Vulnerability

Added Nov. 3, 2021 Due Nov. 17, 2021 CVE-2020-15999
Overdue Google / Chrome FreeType CWE-787

Description

Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.

Required Action

Apply updates per vendor instructions.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
9 months, 4 weeks ago