First published: Sun Jul 23 2017(Updated: )
FontForge 20161012 is vulnerable to a buffer over-read in ValidatePostScriptFontName (parsettf.c) resulting in DoS or code execution via a crafted otf file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fonts | =20161012 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11573 is a medium severity vulnerability due to a buffer over-read that could lead to denial of service or arbitrary code execution.
To fix CVE-2017-11573, update FontForge to the latest version that addresses this vulnerability.
CVE-2017-11573 can lead to denial of service or arbitrary code execution when processing a crafted otf file.
CVE-2017-11573 specifically affects FontForge version 20161012.
Currently, the best option for CVE-2017-11573 is to upgrade to a patched version of FontForge to mitigate the risk.