CVE-2019-15785: Buffer Overflow
FontForge 20190813 through 20190820 has a buffer overflow in PrefsUILoadPrefs in prefs.c.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this FontForge vulnerability?
The vulnerability ID for this FontForge vulnerability is CVE-2019-15785.
What is the severity of CVE-2019-15785?
The severity of CVE-2019-15785 is critical.
How does the vulnerability manifest in FontForge?
The vulnerability manifests as a buffer overflow in the PrefsUI_LoadPrefs function in the prefs.c file of FontForge versions 20190813 through 20190820.
What is the affected software?
The affected software is FontForge version 20190813 through 20190820.
Is there a fix available for this vulnerability?
Yes, a fix is available for this vulnerability. It can be found in the following links: [GitHub commit](https://github.com/fontforge/fontforge/commit/626f751752875a0ddd74b9e217b6f4828713573c), [GitHub pull request](https://github.com/fontforge/fontforge/pull/3886), [Gentoo security advisory](https://security.gentoo.org/glsa/202004-14).