ALAS2-2020-1565

Related Vulnerabilities: CVE-2020-15999  

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (CVE-2020-15999)

ALAS2-2020-1565


Amazon Linux 2 Security Advisory: ALAS-2020-1565
Advisory Release Date: 2020-12-08 20:55 Pacific
Advisory Updated Date: 2020-12-08 22:21 Pacific
Severity: Important
References: CVE-2020-15999 

Issue Overview:

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (CVE-2020-15999)


Affected Packages:

freetype


Issue Correction:
Run yum update freetype to update your system.

New Packages:
aarch64:
    freetype-2.8-14.amzn2.1.aarch64
    freetype-demos-2.8-14.amzn2.1.aarch64
    freetype-devel-2.8-14.amzn2.1.aarch64
    freetype-debuginfo-2.8-14.amzn2.1.aarch64

i686:
    freetype-2.8-14.amzn2.1.i686
    freetype-demos-2.8-14.amzn2.1.i686
    freetype-devel-2.8-14.amzn2.1.i686
    freetype-debuginfo-2.8-14.amzn2.1.i686

src:
    freetype-2.8-14.amzn2.1.src

x86_64:
    freetype-2.8-14.amzn2.1.x86_64
    freetype-demos-2.8-14.amzn2.1.x86_64
    freetype-devel-2.8-14.amzn2.1.x86_64
    freetype-debuginfo-2.8-14.amzn2.1.x86_64