LWN.net Logo

fontforge: code execution

Package(s):fontforge CVE #(s):CVE-2010-4259
Created:December 14, 2010 Updated:January 23, 2012
Description: From the CVE entry:

Stack-based buffer overflow in FontForge 20100501 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long CHARSET_REGISTRY header in a BDF font file.

Alerts:
Debian DSA-2253-1 2011-06-03
Fedora FEDORA-2010-18577 2010-12-05
Fedora FEDORA-2010-18573 2010-12-05
Gentoo 201201-08 2012-01-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds