Heap-Based Buffer Over-Read Vulnerability in FontForge Software by FontForge
CVE-2017-11569
7.8HIGH
What is CVE-2017-11569?
FontForge 20161012 is susceptible to a heap-based buffer over-read in the 'readttfcopyrights' function within 'parsettf.c'. This vulnerability can be exploited by an attacker using a crafted OpenType font (OTF) file, potentially leading to denial of service conditions or execution of arbitrary code.
