Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-5395

Опубликовано: 03 янв. 2020
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.

An out-of-bounds write was discovered in fontforge while parsing SFD files containing very large LayerCount tokens. The flaw allows an attacker to overwrite data before a buffer allocated on the heap, thus causing the application to crash or execute arbitrary code.

Отчет

Impact of the flaw set to Moderate since upstream does not consider a network-facing application that accepts untrusted font files as a reasonable use of fontforge tool/library, making the impact of a possible exploitation of this flaw smaller.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6fontforgeOut of support scope
Red Hat Enterprise Linux 7fontforgeFixedRHSA-2020:396629.09.2020
Red Hat Enterprise Linux 8fontforgeFixedRHSA-2020:192128.04.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1790041fontforge: out-of-bounds write in SFD_GetFontMetaData function in sfd.c

EPSS

Процентиль: 51%
0.00279
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 6 лет назад

FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.

CVSS3: 8.8
nvd
около 6 лет назад

FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.

CVSS3: 8.8
debian
около 6 лет назад

FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd. ...

CVSS3: 8.8
github
больше 3 лет назад

FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.

oracle-oval
больше 5 лет назад

ELSA-2020-3966: fontforge security update (MODERATE)

EPSS

Процентиль: 51%
0.00279
Низкий

8.8 High

CVSS3