[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

254492

 
 

909

 
 

198541

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2020-1514 --- fontforge

ID: oval:org.secpod.oval:def:1700429Date: (C)2020-11-05   (M)2024-03-14
Class: PATCHFamily: unix




An out-of-bounds write was discovered in fontforge while parsing SFD files containing very large LayerCount tokens. The flaw allows an attacker to overwrite data before a buffer allocated on the heap, thus causing the application to crash or execute arbitrary code

Platform:
Amazon Linux 2
Product:
fontforge
Reference:
ALAS2-2020-1514
CVE-2020-5395
CVE    1
CVE-2020-5395

© SecPod Technologies