{"id":"CVE-2017-8287","details":"FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in psaux/psobjs.c.","modified":"2026-05-30T09:15:57.544707Z","published":"2017-04-27T00:59:00.320Z","related":["SUSE-SU-2018:0414-1","SUSE-SU-2018:0462-1","SUSE-SU-2025:20204-1"],"references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/99091"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuapr2020.html"},{"type":"ADVISORY","url":"http://www.debian.org/security/2017/dsa-3839"},{"type":"ADVISORY","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=941"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201706-14"},{"type":"ADVISORY","url":"https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"},{"type":"FIX","url":"http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=3774fc08b502c3e685afca098b6e8a195aded6a0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/aseprite/freetype2","events":[{"introduced":"0"},{"last_affected":"069083cccd73d1d68da68116c8d050bb62cdfe0e"}],"database_specific":{"source":"CPE_RANGE","extracted_events":[{"introduced":"0"},{"last_affected":"2.7.1"}],"cpe":"cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*"}}],"versions":["VER-2-7-1","VER-2-7","VER-2-6-4","VER-2-6-3","VER-2-6-2","VER-2-6-1","VER-2-6","VER-2-5-5","VER-2-5-4","VER-2-5-3","VER-2-5-2","VER-2-5-1","VER-2-5-0-1","VER-2-5-0","VER-2-4-12","VER-2-4-12-beta","VER-2-4-11","VER-2-4-10","VER-2-4-9","VER-2-4-8","VER-2-4-7","VER-2-4-6","VER-2-4-5","VER-2-4-4","VER-2-4-3","VER-2-4-2","VER-2-4-1","VER-2-4-0","VER-2-3-12","VER-2-3-11","VER-2-3-10","VER-2-3-9","VER-2-3-8","VER-2-3-7","VER-2-3-6","VER-2-3-5-REAL","VER-2-3-5","VER-2-3-4","VER-2-3-3","VER-2-3-2","VER-2-3-1-FINAL","VER-2-3-1","VER-2-3-0-FINAL","VER-2-3-0-RC2","VER-2-3-0","VER-2-3-0-RC1","VER-2-2-1","VER-2-2-0-RC4","VER-2-2-0","VER-2-2-0-RC3","VER-2-2-0-RC2","VER-2-2-0-RC1","DATE-050920","VER-2-1-10","VER-2-1-9","VER-2-1-8","VER-2-1-8-RC1","import","VER-2-1-7","VER-2-1-6","VER-2-1-5-RC1","start","VER-2-1-4","VER-2-1-4-RC2","VER-2-1-4-RC1","VER-2-1-3","VER-2-1-3-RC3","VER-2-1-3-RC2","VER-2-1-3-RC1","VER-2-1-2","VER-2-1-2-RC1","VER-2-1-1","VER-2-1-1-RC1","freetype","VER-2-1-0","VER-2-0-8","VER-2-0-7","VER-2-0-6","PRE-2-0-6","VER-2-0-5","freetype2","VER-2-0-4","VER-2-0-3","VER-2-0-2","VER-2-0-2-TEST","VER-2-0-1","PRE-2-0-1","VER-2-0","RELEASE-2-0","BETA-8","BETA-7","BETA-6","BETA-5","VER-2-BETA4","VER-2-BETA3","VER-2-BETA2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-8287.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/freetype/freetype","events":[{"introduced":"0"},{"last_affected":"069083cccd73d1d68da68116c8d050bb62cdfe0e"}],"database_specific":{"source":"CPE_RANGE","extracted_events":[{"introduced":"0"},{"last_affected":"2.7.1"}],"cpe":"cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*"}}],"versions":["VER-2-7-1","VER-2-7","VER-2-6-4","VER-2-6-3","VER-2-6-2","VER-2-6-1","VER-2-6","VER-2-5-5","VER-2-5-4","VER-2-5-3","VER-2-5-2","VER-2-5-1","VER-2-5-0-1","VER-2-5-0","VER-2-4-12","VER-2-4-12-beta","VER-2-4-11","VER-2-4-10","VER-2-4-9","VER-2-4-8","VER-2-4-7","VER-2-4-6","VER-2-4-5","VER-2-4-4","VER-2-4-3","VER-2-4-2","VER-2-4-1","VER-2-4-0","VER-2-3-12","VER-2-3-11","VER-2-3-10","VER-2-3-9","VER-2-3-8","VER-2-3-7","VER-2-3-6","VER-2-3-5-REAL","VER-2-3-5","VER-2-3-4","VER-2-3-3","VER-2-3-2","VER-2-3-1-FINAL","VER-2-3-1","VER-2-3-0-FINAL","VER-2-3-0-RC2","VER-2-3-0","VER-2-3-0-RC1","VER-2-2-1","VER-2-2-0-RC4","VER-2-2-0","VER-2-2-0-RC3","VER-2-2-0-RC2","VER-2-2-0-RC1","DATE-050920","VER-2-1-10","VER-2-1-9","VER-2-1-8","VER-2-1-8-RC1","import","VER-2-1-7","VER-2-1-6","VER-2-1-5-RC1","start","VER-2-1-4","VER-2-1-4-RC2","VER-2-1-4-RC1","VER-2-1-3","VER-2-1-3-RC3","VER-2-1-3-RC2","VER-2-1-3-RC1","VER-2-1-2","VER-2-1-2-RC1","VER-2-1-1","VER-2-1-1-RC1","freetype","VER-2-1-0","VER-2-0-8","VER-2-0-7","VER-2-0-6","PRE-2-0-6","VER-2-0-5","freetype2","VER-2-0-4","VER-2-0-3","VER-2-0-2","VER-2-0-2-TEST","VER-2-0-1","PRE-2-0-1","VER-2-0","RELEASE-2-0","BETA-8","BETA-7","BETA-6","BETA-5","VER-2-BETA4","VER-2-BETA3","VER-2-BETA2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-8287.json"}},{"ranges":[{"type":"GIT","repo":"https://gitlab.freedesktop.org/freetype/freetype","events":[{"introduced":"0"},{"last_affected":"069083cccd73d1d68da68116c8d050bb62cdfe0e"}],"database_specific":{"source":"CPE_RANGE","extracted_events":[{"introduced":"0"},{"last_affected":"2.7.1"}],"cpe":"cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*"}}],"versions":["VER-2-7-1","VER-2-7","VER-2-6-4","VER-2-6-3","VER-2-6-2","VER-2-6-1","VER-2-6","VER-2-5-5","VER-2-5-4","VER-2-5-3","VER-2-5-2","VER-2-5-1","VER-2-5-0-1","VER-2-5-0","VER-2-4-12","VER-2-4-12-beta","VER-2-4-11","VER-2-4-10","VER-2-4-9","VER-2-4-8","VER-2-4-7","VER-2-4-6","VER-2-4-5","VER-2-4-4","VER-2-4-3","VER-2-4-2","VER-2-4-1","VER-2-4-0","VER-2-3-12","VER-2-3-11","VER-2-3-10","VER-2-3-9","VER-2-3-8","VER-2-3-7","VER-2-3-6","VER-2-3-5-REAL","VER-2-3-5","VER-2-3-4","VER-2-3-3","VER-2-3-2","VER-2-3-1-FINAL","VER-2-3-1","VER-2-3-0-FINAL","VER-2-3-0-RC2","VER-2-3-0","VER-2-3-0-RC1","VER-2-2-1","VER-2-2-0-RC4","VER-2-2-0","VER-2-2-0-RC3","VER-2-2-0-RC2","VER-2-2-0-RC1","DATE-050920","VER-2-1-10","VER-2-1-9","VER-2-1-8","VER-2-1-8-RC1","import","VER-2-1-7","VER-2-1-6","VER-2-1-5-RC1","start","VER-2-1-4","VER-2-1-4-RC2","VER-2-1-4-RC1","VER-2-1-3","VER-2-1-3-RC3","VER-2-1-3-RC2","VER-2-1-3-RC1","VER-2-1-2","VER-2-1-2-RC1","VER-2-1-1","VER-2-1-1-RC1","freetype","VER-2-1-0","VER-2-0-8","VER-2-0-7","VER-2-0-6","PRE-2-0-6","VER-2-0-5","freetype2","VER-2-0-4","VER-2-0-3","VER-2-0-2","VER-2-0-2-TEST","VER-2-0-1","PRE-2-0-1","VER-2-0","RELEASE-2-0","BETA-8","BETA-7","BETA-6","BETA-5","VER-2-BETA4","VER-2-BETA3","VER-2-BETA2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-8287.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}