CVE-2017-11574: Buffer Overflow
FontForge 20161012 is vulnerable to a heap-based buffer overflow in readcffset (parsettf.c) resulting in DoS or code execution via a crafted otf file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11574?
CVE-2017-11574 is classified as a critical vulnerability due to its potential for code execution and denial of service.
How do I fix CVE-2017-11574?
To fix CVE-2017-11574, upgrade FontForge to a version later than 20161012 that addresses the heap-based buffer overflow.
What is the impact of CVE-2017-11574?
The impact of CVE-2017-11574 includes the possibility of remote code execution and system denial of service when processing a specially crafted otf file.
What versions of FontForge are affected by CVE-2017-11574?
CVE-2017-11574 affects FontForge version 20161012 only.
How can I determine if my system is vulnerable to CVE-2017-11574?
You can determine if your system is vulnerable by checking if FontForge version 20161012 is installed and if it is processing potentially malicious otf files.