CVE-2017-8105: Debian Linux

Critical severity, CVSS 9.8. EPSS: 4.4% chance of exploitation in the next 30 days.

FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.

Affected products

  • Debian Debian Linux: version 8.0 only
  • FreeType FreeType: before 2.7.1 (fixed in 2.7.1)

Published 2017-04-24. Last modified 2026-06-17.