USN-3409-1
Dashboard / Vulnerabilities / USN-3409-1
USN-3409-1
Summary: fontforge vulnerabilities
Details: It was discovered that FontForge was vulnerable to a heap-based buffer over-read. A remote attacker could use a crafted file to DoS or execute arbitrary code. (CVE-2017-11568, CVE-2017-11569, CVE-2017-11572) It was discovered that FontForge was vulnerable to a stack-based buffer overflow. A remote attacker could use a crafted file to DoS or execute arbitrary code. (CVE-2017-11571) It was discovered that FontForge was vulnerable to a heap-based buffer overflow. A remote attacker could use a crafted file to DoS or execute arbitrary code. (CVE-2017-11574) It was discovered that FontForge was vulnerable to a buffer over-read. A remote attacker could use a crafted file to DoS or execute arbitrary code. (CVE-2017-11575, CVE-2017-11577) It was discovered that FontForge wasn't correctly checking the sign of a vector size. A remote attacker could use a crafted file to DoS. (CVE-2017-11576)
References: https://ubuntu.com/security/notices/USN-3409-1, https://ubuntu.com/security/CVE-2017-11568, https://ubuntu.com/security/CVE-2017-11569, https://ubuntu.com/security/CVE-2017-11571, https://ubuntu.com/security/CVE-2017-11572, https://ubuntu.com/security/CVE-2017-11574, https://ubuntu.com/security/CVE-2017-11575, https://ubuntu.com/security/CVE-2017-11576, https://ubuntu.com/security/CVE-2017-11577
Affected packages
Package
Name: fontforge
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
