Buffer Over-read Vulnerability in FontForge Product by FontForge
CVE-2017-11573
7.8HIGH
What is CVE-2017-11573?
The vulnerability found in FontForge version 20161012 can lead to a buffer over-read during the processing of PostScript font names in the ValidatePostScriptFontName function found in parsettf.c. An attacker can exploit this flaw by crafting a malicious OTF file, potentially leading to denial of service (DoS) conditions or executing arbitrary code. Developers and users of FontForge should take immediate steps to mitigate this risk by updating to the latest version and following best security practices.
