Описание
FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of scanlines within SGI files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27920.
A flaw was found in FontForge. This vulnerability, a heap-based buffer overflow, allows a remote attacker to execute arbitrary code. Exploitation requires user interaction, such as opening a malicious SGI (Silicon Graphics Image) file, which triggers improper data length validation during scanline parsing, leading to memory corruption.
Отчет
This vulnerability is rated Important for Red Hat products. Exploitation requires user interaction, specifically opening a specially crafted SGI file in FontForge. This impacts systems where FontForge is installed and used to process untrusted image files, such as in desktop environments.
Меры по смягчению последствий
Avoid opening untrusted SGI (Silicon Graphics Image) files with FontForge. If FontForge is not essential for system operation, consider removing the package to eliminate the attack surface.
To remove FontForge:
For Red Hat Enterprise Linux 7 and 8:
sudo yum remove fontforge
For Red Hat Enterprise Linux 9 and 10, and Fedora:
sudo dnf remove fontforge
Removing FontForge may affect other applications that depend on its functionality. A system restart may be required to ensure all related processes are terminated.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | fontforge | Affected | ||
| Red Hat Enterprise Linux 6 | fontforge | Out of support scope | ||
| Red Hat Enterprise Linux 7 | fontforge | Affected | ||
| Red Hat Enterprise Linux 8 | fontforge | Affected | ||
| Red Hat Enterprise Linux 9 | fontforge | Affected |
Показывать по
Дополнительная информация
Статус:
7.8 High
CVSS3
Связанные уязвимости
FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of scanlines within SGI files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27920.
FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of scanlines within SGI files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27920.
FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Co ...
FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of scanlines within SGI files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27920.
7.8 High
CVSS3