It was discovered that FontForge was vulnerable to a heap-based buffer over-read. A remote attacker could use a crafted file to DoS or execute arbitrary code. (CVE-2017-11568, CVE-2017-11569, CVE-2017-11572)
It was discovered that FontForge was vulnerable to a stack-based buffer overflow. A remote attacker could use a crafted file to DoS or execute arbitrary code. (CVE-2017-11571)
It was discovered that FontForge was vulnerable to a heap-based buffer overflow. A remote attacker could use a crafted file to DoS or execute arbitrary code. (CVE-2017-11574)
It was discovered that FontForge was vulnerable to a buffer over-read. A remote attacker could use a crafted file to DoS or execute arbitrary code. (CVE-2017-11575, CVE-2017-11577)
It was discovered that FontForge wasn't correctly checking the sign of a vector size. A remote attacker could use a crafted file to DoS. (CVE-2017-11576)
{ "binaries": [ { "binary_name": "fontforge", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "fontforge-common", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "fontforge-dbg", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "fontforge-dbgsym", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "fontforge-nox", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "fontforge-nox-dbgsym", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "libfontforge-dev", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "libfontforge-dev-dbgsym", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "libfontforge1", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "libfontforge1-dbgsym", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "libgdraw4", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "libgdraw4-dbgsym", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "python-fontforge", "binary_version": "20120731.b-5ubuntu0.1" }, { "binary_name": "python-fontforge-dbgsym", "binary_version": "20120731.b-5ubuntu0.1" } ], "availability": "No subscription required" }