Heap-based Buffer Overflow in FontForge SFD File Parsing
CVE-2025-15272
8.8HIGH
What is CVE-2025-15272?
The vulnerability in FontForge arises from improper validation of user-supplied data length during the parsing of SFD files. This flaw allows attackers to exploit the system by executing arbitrary code if the target user visits a malicious webpage or opens a compromised file. Attackers can gain control within the context of the user's environment, leading to potential unauthorized actions.
Affected Version(s)
FontForge aca4f524c6cb14cdc7bc4cd493492a33f5154797
