[ALAS2-2020-1565] Amazon Linux 2 2017.12 - ALAS2-2020-1565: important priority package update for freetype

Severity Important
Affected Packages 12
CVEs 1

Package updates are available for Amazon Linux 2 that fix the following vulnerabilities:
CVE-2020-15999:
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
1890210: CVE-2020-15999 freetype: Heap-based buffer overflow due to integer truncation in Load_SBit_Png

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/freetype?arch=x86_64&distro=amazonlinux-2 amazonlinux freetype < 2.8-14.amzn2.1 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/freetype?arch=i686&distro=amazonlinux-2 amazonlinux freetype < 2.8-14.amzn2.1 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/freetype?arch=aarch64&distro=amazonlinux-2 amazonlinux freetype < 2.8-14.amzn2.1 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/freetype-devel?arch=x86_64&distro=amazonlinux-2 amazonlinux freetype-devel < 2.8-14.amzn2.1 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/freetype-devel?arch=i686&distro=amazonlinux-2 amazonlinux freetype-devel < 2.8-14.amzn2.1 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/freetype-devel?arch=aarch64&distro=amazonlinux-2 amazonlinux freetype-devel < 2.8-14.amzn2.1 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/freetype-demos?arch=x86_64&distro=amazonlinux-2 amazonlinux freetype-demos < 2.8-14.amzn2.1 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/freetype-demos?arch=i686&distro=amazonlinux-2 amazonlinux freetype-demos < 2.8-14.amzn2.1 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/freetype-demos?arch=aarch64&distro=amazonlinux-2 amazonlinux freetype-demos < 2.8-14.amzn2.1 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/freetype-debuginfo?arch=x86_64&distro=amazonlinux-2 amazonlinux freetype-debuginfo < 2.8-14.amzn2.1 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/freetype-debuginfo?arch=i686&distro=amazonlinux-2 amazonlinux freetype-debuginfo < 2.8-14.amzn2.1 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/freetype-debuginfo?arch=aarch64&distro=amazonlinux-2 amazonlinux freetype-debuginfo < 2.8-14.amzn2.1 amazonlinux-2 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...