FontForge 20161012 is vulnerable to a buffer over-read in strnmatch (char.c) resulting in DoS or code execution via a crafted otf file, related to a call from the readttfcopyrights function in parsettf.c.
{ "binaries": [ { "binary_name": "fontforge", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "fontforge-common", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "fontforge-dbg", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "fontforge-dbgsym", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "fontforge-nox", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "fontforge-nox-dbgsym", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "libfontforge-dev", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "libfontforge-dev-dbgsym", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "libfontforge1", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "libfontforge1-dbgsym", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "libgdraw4", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "libgdraw4-dbgsym", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "python-fontforge", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "python-fontforge-dbgsym", "binary_version": "20120731.b-5ubuntu0.1" } ], "ubuntu_priority": "medium", "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "fontforge", "binary_version": "20120731.b-7.1ubuntu0.1" }, { "binary_name": "fontforge-common", "binary_version": "20120731.b-7.1ubuntu0.1" }, { "binary_name": "fontforge-dbg", "binary_version": "20120731.b-7.1ubuntu0.1" }, { "binary_name": "fontforge-dbgsym", "binary_version": "20120731.b-7.1ubuntu0.1" }, { "binary_name": "fontforge-nox", "binary_version": "20120731.b-7.1ubuntu0.1" }, { "binary_name": "fontforge-nox-dbgsym", "binary_version": "20120731.b-7.1ubuntu0.1" }, { "binary_name": "libfontforge-dev", "binary_version": "20120731.b-7.1ubuntu0.1" }, { "binary_name": "libfontforge-dev-dbgsym", "binary_version": "20120731.b-7.1ubuntu0.1" }, { "binary_name": "libfontforge1", "binary_version": "20120731.b-7.1ubuntu0.1" }, { "binary_name": "libfontforge1-dbgsym", "binary_version": "20120731.b-7.1ubuntu0.1" }, { "binary_name": "libgdraw4", "binary_version": "20120731.b-7.1ubuntu0.1" }, { "binary_name": "libgdraw4-dbgsym", "binary_version": "20120731.b-7.1ubuntu0.1" }, { "binary_name": "python-fontforge", "binary_version": "20120731.b-7.1ubuntu0.1" } ], "ubuntu_priority": "medium", "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "fontforge", "binary_version": "1:20170731~dfsg-1" }, { "binary_name": "fontforge-common", "binary_version": "1:20170731~dfsg-1" }, { "binary_name": "fontforge-dbg", "binary_version": "1:20170731~dfsg-1" }, { "binary_name": "fontforge-doc", "binary_version": "1:20170731~dfsg-1" }, { "binary_name": "fontforge-nox", "binary_version": "1:20170731~dfsg-1" }, { "binary_name": "libfontforge-dev", "binary_version": "1:20170731~dfsg-1" }, { "binary_name": "libfontforge2", "binary_version": "1:20170731~dfsg-1" }, { "binary_name": "libgdraw5", "binary_version": "1:20170731~dfsg-1" }, { "binary_name": "python-fontforge", "binary_version": "1:20170731~dfsg-1" } ], "ubuntu_priority": "medium", "availability": "No subscription required" }