FontForge 20161012 is vulnerable to a buffer over-read in getsid (parsettf.c) resulting in DoS or code execution via a crafted otf file.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "20120731.b-5ubuntu0.1", "binary_name": "fontforge" }, { "binary_version": "20120731.b-5ubuntu0.1", "binary_name": "fontforge-common" }, { "binary_version": "20120731.b-5ubuntu0.1", "binary_name": "fontforge-nox" }, { "binary_version": "20120731.b-5ubuntu0.1", "binary_name": "libfontforge-dev" }, { "binary_version": "20120731.b-5ubuntu0.1", "binary_name": "libfontforge1" }, { "binary_version": "20120731.b-5ubuntu0.1", "binary_name": "libgdraw4" }, { "binary_version": "20120731.b-5ubuntu0.1", "binary_name": "python-fontforge" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "20120731.b-7.1ubuntu0.1", "binary_name": "fontforge" }, { "binary_version": "20120731.b-7.1ubuntu0.1", "binary_name": "fontforge-common" }, { "binary_version": "20120731.b-7.1ubuntu0.1", "binary_name": "fontforge-nox" }, { "binary_version": "20120731.b-7.1ubuntu0.1", "binary_name": "libfontforge-dev" }, { "binary_version": "20120731.b-7.1ubuntu0.1", "binary_name": "libfontforge1" }, { "binary_version": "20120731.b-7.1ubuntu0.1", "binary_name": "libgdraw4" }, { "binary_version": "20120731.b-7.1ubuntu0.1", "binary_name": "python-fontforge" } ] }