Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-37011. PoCs published by Cody Winkler.
AI-analyzed exploit summary This exploit generates a malformed TTF file to trigger a heap corruption vulnerability in Gnome Fonts Viewer 3.34.0, leading to a denial-of-service condition via an infinite malloc loop.
Description
Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger an out-of-bounds write by crafting a malicious TTF font file. Attackers can generate a specially crafted TTF file with an oversized pattern to exhaust memory through repeated malloc() calls and potentially crash the gnome-font-viewer process.
Exploits (1)
This exploit generates a malformed TTF file to trigger a heap corruption vulnerability in Gnome Fonts Viewer 3.34.0, leading to a denial-of-service condition via an infinite malloc loop.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H