Heap buffer overflow in CefSharp
Moderate severity
GitHub Reviewed
Published
Oct 25, 2020
in
cefsharp/CefSharp
•
Updated Feb 15, 2024
Description
Reviewed
Oct 27, 2020
Published to the GitHub Advisory Database
Oct 27, 2020
Published by the National Vulnerability Database
Nov 3, 2020
Last updated
Feb 15, 2024
Impact
A memory corruption bug(Heap overflow) in the FreeType font rendering library.
As per https://www.secpod.com/blog/chrome-zero-day-under-active-exploitation-patch-now/
Google is aware of reports that an exploit for CVE-2020-15999 exists in the wild.
Patches
Upgrade to 85.3.130 or higher
References
To review the
CEF/Chromium
patch see https://bitbucket.org/chromiumembedded/cef/commits/cd6cbe008b127990036945fb75e7c2c1594ab10dReferences