CVE-2020-25690Improper Restriction of Operations within the Bounds of a Memory Buffer in Fontforge

Severity
8.8HIGHNVD
EPSS
0.8%
top 25.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 23
Latest updateMay 24

Description

An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens. This flaw allows an attacker to manipulate the memory allocated on the heap, causing the application to crash or execute arbitrary code. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDfontforge/fontforge< 20200314
CVEListV5fontforge/fontforgefontforge before 20200314

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8m73-qxc4-m26m: An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens2022-05-24
OSV
CVE-2020-25690: An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens2021-02-23

📋Vendor Advisories

2
Red Hat
fontforge: SFD_GetFontMetaData() insufficient CVE-2020-5395 backport2020-01-21
Debian
CVE-2020-25690: fontforge - An out-of-bounds write flaw was found in FontForge in versions before 20200314 w...2020

💬Community

1
Bugzilla
CVE-2020-25690 fontforge: SFD_GetFontMetaData() insufficient CVE-2020-5395 backport2020-10-30
CVE-2020-25690 — Fontforge vulnerability | cvebase