CVE-2020-25690: Buffer Overflow

Published Oct 30, 2020
·
Updated

An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens. This flaw allows an attacker to manipulate the memory allocated on the heap, causing the application to crash or execute arbitrary code. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Other sources

RHSA-2020:1921 fixed CVE-2020-5395 by backporting an upstream patch. However, this backport was later found to introduce another issue causing an incorrect amount of heap memory space to be allocated, which could ultimately result in out of bounds heap memory manipulation when processing a specially crafted font file. This new problem was fixed upstream in a subsequent patch and, to our knowledge, no versioned upstream release was ever affected. Unfortunately, the Red Hat Enterprise Linux 8 fontforge package is affected.

Original first patch: https://github.com/fontforge/fontforge/commit/048a91e2682c1a8936ae34dbc7bd70291ec05410

Additional patch required: https://github.com/fontforge/fontforge/commit/b96273acc691ac8a36c6a8dd4de8e6edd7eaae59

Red Hat

Affected Software

2 affected componentsFixes available
redhat/fontforge<20200314
20200314
FontForge FontForge<20200314

Event History

Feb 23, 2021
CVE Published
via MITRE·03:40 AM
Data Sourced
via MITRE·03:40 AM
DescriptionWeakness

Frequently Asked Questions

1

What is the vulnerability ID for this issue?

The vulnerability ID for this issue is CVE-2020-25690.

2

What is the severity level of CVE-2020-25690?

CVE-2020-25690 has a severity level of 8.8 (high).

3

How does CVE-2020-25690 affect FontForge?

CVE-2020-25690 affects FontForge versions before 20200314.

4

What is the impact of CVE-2020-25690?

CVE-2020-25690 allows an attacker to manipulate the memory allocated on the heap, causing the application to crash or execute arbitrary code.

5

How can I fix CVE-2020-25690?

To fix CVE-2020-25690, it is recommended to update FontForge to version 20200314 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203