Umbra Wiki cve cve/CVE-2020-15999
Back to wiki

CVE-2020-15999 — Google Chrome FreeType Heap Buffer Overflow Vulnerability

provenance: imported · CVE: CVE-2020-15999 · CWE: CWE-787

CVE-2020-15999: Google Chrome FreeType Heap Buffer Overflow Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Google
Product Chrome FreeType
Date added 2021-11-03
Due date 2021-11-17
Ransomware campaign use Unknown

Description

Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2020-15999

Weakness behind it

CISA records this vulnerability as an instance of CWE-787. From there the chain continues into CAPEC attack patterns and ATT&CK techniques, all inside this corpus.

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2020-15999
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

See all 1,745 pages under Vulnerabilities (CVE) →