Stack-Based Buffer Overflow in FontForge Leading to Potential Code Execution
CVE-2017-11571
7.8HIGH
What is CVE-2017-11571?
FontForge version 20161012 is susceptible to a stack-based buffer overflow within the addnibble function found in parsettf.c. This vulnerability can be exploited by providing a specially crafted OpenType font (otf) file, potentially leading to a denial-of-service (DoS) scenario or enabling remote code execution. The issue highlights the need for proper input validation when handling font files to maintain application security.
