Logo
vulnerabilityCVE-2020-25690
Name
CVE-2020-25690
Source
NVD ( link)Debian ( link)
Description
An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens. This flaw allows an attacker to manipulate the memory allocated on the heap, causing the application to crash or execute arbitrary code. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
fontforge
Patched

Vulnerability Ratings#


8.8
CVSSv31
6.8
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
20251009
Not Affected
yocto
scarthgap
20230101
Not Affected

Resolved with patches#


fontforge (yocto:kirkstone)

#
Title
Author
Resolve
1
Fix crash on exit introduced in previous commit
Fredrick Brennan <copypaste@kittens.ph>
CVE-2020-25690
CVE-2020-5395
CVE-2020-5496
2
Fix for #4084 Use-after-free (heap) in the
Skef Iterum <unknown>
CVE-2020-25690
CVE-2020-5395
CVE-2020-5496