MGASA-2018-0037
Dashboard / Vulnerabilities / MGASA-2018-0037
MGASA-2018-0037
Summary: Updated fontforge packages fix security vulnerability
Details: It was discovered that FontForge, a font editor, did not correctly validate its input. An attacker could use this flaw by tricking a user into opening a maliciously crafted OpenType font file, thus causing a denial-of-service via application crash, or execution of arbitrary code (CVE-2017-11568, CVE-2017-11569, CVE-2017-11571, CVE-2017-11572, CVE-2017-11574, CVE-2017-11575, CVE-2017-11576, CVE-2017-11577).
References: https://advisories.mageia.org/MGASA-2018-0037.html, https://bugs.mageia.org/show_bug.cgi?id=21634, https://www.debian.org/security/2017/dsa-3958
Affected packages
Package
Name: fontforge
Purl: pkg:rpm/mageia/fontforge?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
