CVE-2017-11569
published 2017-07-23CVE-2017-11569: FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a crafted otf file.
PriorityP432high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.41%
69.6th percentile
FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a crafted otf file.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | fontforge | < fontforge 1:20170731~dfsg-1 (bookworm) | fontforge 1:20170731~dfsg-1 (bookworm) |
| fontforge | fontforge | — | — |
| fontforge | fontforge | >= 0 < 1:20170731~dfsg-1 | 1:20170731~dfsg-1 |
| fontforge | fontforge | >= 0 < 1:20170731~dfsg-1 | 1:20170731~dfsg-1 |
| fontforge | fontforge | >= 0 < 1:20170731~dfsg-1 | 1:20170731~dfsg-1 |
| fontforge | fontforge | >= 0 < 1:20170731~dfsg-1 | 1:20170731~dfsg-1 |
| fontforge | fontforge | >= 0 < 20120731.b-5ubuntu0.1 | 20120731.b-5ubuntu0.1 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xvh7-cvv2-7h78: FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf
ghsa_unreviewed·2022-05-13
CVE-2017-11569 [HIGH] CWE-125 GHSA-xvh7-cvv2-7h78: FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf
FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a crafted otf file.
OSV
fontforge vulnerabilities
osv·2017-09-04·CVSS 7.8
CVE-2017-11568 [HIGH] fontforge vulnerabilities
fontforge vulnerabilities
It was discovered that FontForge was vulnerable to a heap-based buffer
over-read. A remote attacker could use a crafted file to DoS or execute
arbitrary code. (CVE-2017-11568, CVE-2017-11569, CVE-2017-11572)
It was discovered that FontForge was vulnerable to a stack-based buffer
overflow. A remote attacker could use a crafted file to DoS or execute
arbitrary code. (CVE-2017-11571)
It was discovered that FontForge was vulnerable to a heap-based buffer
overflow. A remote attacker could use a crafted file to DoS or execute
arbitrary code. (CVE-2017-11574)
It was discovered that FontForge was vulnerable to a buffer over-read.
A remote attacker could use a crafted file to DoS or execute arbitrary
code. (CVE-2017-11575, CVE-2017-11577)
It was discovered that FontFo
OSV
CVE-2017-11569: FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf
osv·2017-07-23·CVSS 7.8
CVE-2017-11569 [HIGH] CVE-2017-11569: FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf
FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a crafted otf file.
Ubuntu
FontForge vulnerabilities
vendor_ubuntu·2017-09-04·CVSS 7.8
CVE-2017-11568 [HIGH] FontForge vulnerabilities
Title: FontForge vulnerabilities
Summary: Several security issues were fixed in FontForge.
It was discovered that FontForge was vulnerable to a heap-based buffer
over-read. A remote attacker could use a crafted file to DoS or execute
arbitrary code. (CVE-2017-11568, CVE-2017-11569, CVE-2017-11572)
It was discovered that FontForge was vulnerable to a stack-based buffer
overflow. A remote attacker could use a crafted file to DoS or execute
arbitrary code. (CVE-2017-11571)
It was discovered that FontForge was vulnerable to a heap-based buffer
overflow. A remote attacker could use a crafted file to DoS or execute
arbitrary code. (CVE-2017-11574)
It was discovered that FontForge was vulnerable to a buffer over-read.
A remote attacker could use a crafted file to DoS or execute arbitrary
cod
Red Hat
fontforge: Heap-buffer over-read in readttfcopyrights function
vendor_redhat·2017-06-14·CVSS 7.8
CVE-2017-11569 [HIGH] CWE-122 fontforge: Heap-buffer over-read in readttfcopyrights function
fontforge: Heap-buffer over-read in readttfcopyrights function
FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a crafted otf file.
Package: fontforge (Red Hat Enterprise Linux 6) - Will not fix
Package: fontforge (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2017-11569: fontforge - FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopy...
vendor_debian·2017·CVSS 7.8
CVE-2017-11569 [HIGH] CVE-2017-11569: fontforge - FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopy...
FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a crafted otf file.
Scope: local
bookworm: resolved (fixed in 1:20170731~dfsg-1)
bullseye: resolved (fixed in 1:20170731~dfsg-1)
forky: resolved (fixed in 1:20170731~dfsg-1)
sid: resolved (fixed in 1:20170731~dfsg-1)
trixie: resolved (fixed in 1:20170731~dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-11569 fontforge: Heap-buffer over-read in readttfcopyrights function
bugzilla·2017-07-26·CVSS 7.8
CVE-2017-11569 [HIGH] CVE-2017-11569 fontforge: Heap-buffer over-read in readttfcopyrights function
CVE-2017-11569 fontforge: Heap-buffer over-read in readttfcopyrights function
FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS via a crafted otf file.
Upstream issue:
https://github.com/fontforge/fontforge/issues/3093
Discussion:
Created fontforge tracking bugs for this issue:
Affects: fedora-all [bug 1475398]
---
Fixed in rawhide build fontforge-20170731-1.fc27
Bugzilla
CVE-2017-11568 CVE-2017-11569 CVE-2017-11570 CVE-2017-11571 CVE-2017-11572 CVE-2017-11573 CVE-2017-11574 CVE-2017-11575 CVE-2017-11576 CVE-2017-11577 fontforge: various flaws [fedora-all]
bugzilla·2017-07-26·CVSS 7.8
CVE-2017-11568 [HIGH] CVE-2017-11568 CVE-2017-11569 CVE-2017-11570 CVE-2017-11571 CVE-2017-11572 CVE-2017-11573 CVE-2017-11574 CVE-2017-11575 CVE-2017-11576 CVE-2017-11577 fontforge: various flaws [fedora-all]
CVE-2017-11568 CVE-2017-11569 CVE-2017-11570 CVE-2017-11571 CVE-2017-11572 CVE-2017-11573 CVE-2017-11574 CVE-2017-11575 CVE-2017-11576 CVE-2017-11577 fontforge: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being f
2017-07-23
Published