CVE-2019-15785Improper Restriction of Operations within the Bounds of a Memory Buffer in Fontforge

Severity
9.8CRITICALNVD
EPSS
0.6%
top 30.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 29
Latest updateMay 24

Description

FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-qp2p-2wx4-5vff: FontForge through 20190801 has a buffer overflow in PrefsUI_LoadPrefs in prefs2022-05-24

📋Vendor Advisories

2
Red Hat
fontforge: buffer overflow in PrefsUI_LoadPrefs in prefs.c2019-09-11
Debian
CVE-2019-15785: fontforge - FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs i...2019

💬Community

2
Bugzilla
CVE-2019-15785 fontforge: buffer overflow in PrefsUI_LoadPrefs in prefs.c [fedora-all]2019-09-11
Bugzilla
CVE-2019-15785 fontforge: buffer overflow in PrefsUI_LoadPrefs in prefs.c2019-09-11
CVE-2019-15785 — Fontforge vulnerability | cvebase