CVE-2020-5496: Buffer Overflow
Published Jan 3, 2020
·Updated
FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesave.c.
Affected Software
2 affected components
FontForge FontForge=20190801
openSUSE Leap=15.1
Event History
Jan 3, 2020
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this FontForge vulnerability?
The vulnerability ID for this FontForge vulnerability is CVE-2020-5496.
2
What is the severity of CVE-2020-5496?
The severity of CVE-2020-5496 is high with a severity value of 8.8.
3
What is the affected software for CVE-2020-5496?
The affected software for CVE-2020-5496 is FontForge version 20190801 and openSUSE Leap version 15.1.
4
What is the CWE ID for CVE-2020-5496?
The CWE ID for CVE-2020-5496 is CWE-119 and CWE-787.
5
How can I fix the vulnerability in FontForge?
To fix the vulnerability in FontForge, update to a version that is not affected.