yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2020-5395
Component Overview
Vulnerability Overview
Name
CVE-2020-5395
Source
NVD (
link
)
Debian (
link
)
Description
FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.
CWEs
CWE-416
Published Date
Jan 3, 2020
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00041.html
Third Party Advisory
https://github.com/fontforge/fontforge/issues/4084
Exploit
https://security.gentoo.org/glsa/202004-14
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00041.html
Third Party Advisory
https://github.com/fontforge/fontforge/issues/4084
Exploit
https://security.gentoo.org/glsa/202004-14
Third Party Advisory
Analysis
#
Affected Component
Analysis
fontforge
Patched
Vulnerability Ratings
#
8.8
CVSSv31
6.8
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
fontforge
yocto
master
20251009
Not Affected
fontforge
yocto
scarthgap
20230101
Not Affected
Resolved with patches
#
fontforge (yocto:kirkstone)
#
Title
Author
Resolve
1
Fix crash on exit introduced in previous commit
Fredrick Brennan <copypaste@kittens.ph>
CVE-2020-25690
CVE-2020-5395
CVE-2020-5496
2
Fix for #4084 Use-after-free (heap) in the
Skef Iterum <unknown>
CVE-2020-25690
CVE-2020-5395
CVE-2020-5496