CVE-2017-11577: High severity fonts vulnerability
Published Jul 23, 2017
·Updated
FontForge 20161012 is vulnerable to a buffer over-read in getsid (parsettf.c) resulting in DoS or code execution via a crafted otf file.
Affected Software
1 affected component
FontForge FontForge=20161012
Remediation
Patch Available
Event History
Jul 23, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11577?
CVE-2017-11577 has a high severity rating due to its potential to cause a denial of service or arbitrary code execution.
2
How do I fix CVE-2017-11577?
To fix CVE-2017-11577, update to the latest version of FontForge that addresses this vulnerability.
3
What type of vulnerability is CVE-2017-11577?
CVE-2017-11577 is classified as a buffer over-read vulnerability.
4
Who is affected by CVE-2017-11577?
CVE-2017-11577 affects users of FontForge version 20161012.
5
What could an attacker exploit in CVE-2017-11577?
An attacker could exploit CVE-2017-11577 by using a crafted OTF file to trigger the buffer over-read.