Review reviewCritical
CVE-2022-33047
otfcc
OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.
- CVSS
- 9.8
- EPSS
- 1.08% 61.9% percentile
- CISA KEV
- Not listed
- Published
- 2022.07.07
OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.
The CVSS severity warrants an early asset and exposure review.
OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.
Confirm exposure before applying a vendor-supported change.
Confirm that otfcc and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.