suse · CVE-2017-8287

Quick triage

Priority: high Published: 2021-05-30 13:55:59 UTC Updated: 2026-04-18 09:05:29 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2017-8287 severity important: SUSE including 46 source package names (2.1.3-6.17:libfreetype6-2.13.3-1.1, beta1:libfreetype6-2.6.3-7.15.1, …), 174 product×package rows across 86 product lines (Container caasp/v4/nginx-ingress-controller, Container suse/sl-micro/6.0/base-os-container, … (86 product lines)): Fixed 124, Known Not Affected 50.

Description:

FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in psaux/psobjs.c.

cvelogic Threat Intelligence