
CVE-2020-25690 – fontforge: SFD_GetFontMetaData() insufficient CVE-2020-5395 backport
https://notcve.org/view.php?id=CVE-2020-25690
04 Nov 2020 — An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens. This flaw allows an attacker to manipulate the memory allocated on the heap, causing the application to crash or execute arbitrary code. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. Se encontró un fallo de escritura fuera de límites en FontForge en versiones anteriores a 20200314 mientras se analizan archi... • https://bugzilla.redhat.com/show_bug.cgi?id=1893188 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2020-5496 – Gentoo Linux Security Advisory 202004-14
https://notcve.org/view.php?id=CVE-2020-5496
03 Jan 2020 — FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesave.c. FontForge versión 20190801, tiene un desbordamiento de búfer en la región heap de la memoria en la función Type2NotDefSplines() en el archivo splinesave.c. Multiple vulnerabilities have been found in FontForge, the worst of which could result in the arbitrary execution of code. Versions less than 20200314 are affected. • http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00041.html • CWE-787: Out-of-bounds Write •

CVE-2020-5395 – fontforge: out-of-bounds write in SFD_GetFontMetaData function in sfd.c
https://notcve.org/view.php?id=CVE-2020-5395
03 Jan 2020 — FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c. FontForge versión 20190801, tiene un uso de la memoria previamente liberada de la función SFD_GetFontMetaData en el archivo sfd.c. An out-of-bounds write was discovered in fontforge while parsing SFD files containing very large LayerCount tokens. The flaw allows an attacker to overwrite data before a buffer allocated on the heap, thus causing the application to crash or execute arbitrary code. FontForge is a font editor for outline and... • http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00041.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-416: Use After Free •

CVE-2019-15785 – Gentoo Linux Security Advisory 202004-14
https://notcve.org/view.php?id=CVE-2019-15785
29 Aug 2019 — FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c. FontForge versión 20190813 hasta la versión 20190820 tiene un desbordamiento de búfer en la función PrefsUI_LoadPrefs en el archivo prefs.c. Multiple vulnerabilities have been found in FontForge, the worst of which could result in the arbitrary execution of code. Versions less than 20200314 are affected. • https://github.com/fontforge/fontforge/commit/626f751752875a0ddd74b9e217b6f4828713573c • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •