CVE-2020-25690
HIGHFontForge < 20200314 - Out-of-Bounds Write via SFD LayerCount Token Parsing
Title source: llmDescription
An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens. This flaw allows an attacker to manipulate the memory allocated on the heap, causing the application to crash or execute arbitrary code. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
References (1)
Core 1
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1893188
Scores
CVSS v3
8.8
EPSS
0.0134
EPSS Percentile
67.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-119
Status
published
Products (1)
fontforge/fontforge
< 20200314
Published
Feb 23, 2021
Tracked Since
Feb 18, 2026