MGASA-2018-0037

Source
https://advisories.mageia.org/MGASA-2018-0037.html
Import Source
https://advisories.mageia.org/MGASA-2018-0037.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2018-0037
Related
Published
2018-01-03T14:22:14Z
Modified
2018-01-03T13:51:50Z
Summary
Updated fontforge packages fix security vulnerability
Details

It was discovered that FontForge, a font editor, did not correctly validate its input. An attacker could use this flaw by tricking a user into opening a maliciously crafted OpenType font file, thus causing a denial-of-service via application crash, or execution of arbitrary code (CVE-2017-11568, CVE-2017-11569, CVE-2017-11571, CVE-2017-11572, CVE-2017-11574, CVE-2017-11575, CVE-2017-11576, CVE-2017-11577).

References
Credits

Affected packages

Mageia:5 / fontforge

Package

Name
fontforge
Purl
pkg:rpm/mageia/fontforge?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0-1.20120731.10.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / fontforge

Package

Name
fontforge
Purl
pkg:rpm/mageia/fontforge?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20161012-4.1.mga6

Ecosystem specific

{
    "section": "core"
}