IBM BladeCenter Advanced Management Module (AMM) has addressed the following vulnerability in freetype2.
CVEID: CVE-2016-10328 DESCRIPTION: Freetype 2 is vulnerable to a heap-based buffer overflow, caused by an out-of-bounds write related to the cff_parser_run function in cff/cffparse.c. By sending a specially request, a remote attacker could overflow a buffer and execute arbitrary code on the system.
CVSS Base Score: 7.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/126666> for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Product
|
Affected Version
—|—
IBM BladeCenter Advanced Management Module (AMM)
|
BPET
Firmware fix versions are available on Fix Central: http://www.ibm.com/support/fixcentral/
Product
|
Fix Version
—|—
IBM BladeCenter Advanced Management Module (AMM)
(ibm_fw_amm_bpet68j-3.68j_anyos_noarch)
|
bpet68j-3.68j
None