CVE-2017-11571: Buffer Overflow
Published Jul 23, 2017
·Updated
FontForge 20161012 is vulnerable to a stack-based buffer overflow in addnibble (parsettf.c) resulting in DoS or code execution via a crafted otf file.
Affected Software
1 affected component
FontForge FontForge=20161012
Remediation
Patch Available
Event History
Jul 23, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11571?
CVE-2017-11571 has a high severity due to its potential for stack-based buffer overflow leading to DoS or arbitrary code execution.
2
How do I fix CVE-2017-11571?
To fix CVE-2017-11571, update FontForge to a version that patches this vulnerability.
3
What causes the CVE-2017-11571 vulnerability?
CVE-2017-11571 is caused by a stack-based buffer overflow in the addnibble function within parsettf.c.
4
In which software version is CVE-2017-11571 found?
CVE-2017-11571 is found in FontForge version 20161012.
5
What are the risks associated with CVE-2017-11571?
The risks of CVE-2017-11571 include potential denial of service or the execution of malicious code via crafted OpenType font files.