USN-3409-1: FontForge vulnerabilities
USN-3409-1: FontForge vulnerabilities Ubuntu Security Notice USN-3409-1 4th September, 2017 fontforge vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were fixed in FontForge. Software description fontforge – font editor Details It was discovered that FontForge was vulnerable to a heap-based bufferover-read. A remote attacker could use a crafted file to DoS or executearbitrary code. (CVE-2017-11568, CVE-2017-11569, CVE-2017-11572) It was discovered that FontForge was vulnerable to a stack-based bufferoverflow. A remote attacker could use a crafted file to DoS or executearbitrary code. (CVE-2017-11571) It was discovered that FontForge was vulnerable to a heap-based bufferoverflow. A remote attacker could use a crafted file to DoS or executearbitrary code. (CVE-2017-11574) It was discovered that FontForge was vulnerable to a buffer over-read.A remote attacker could use a crafted file to DoS or execute [ more… ]