Debian Security Advisory

DSA-3958-1 fontforge -- security update

Date Reported:
29 Aug 2017
Affected Packages:
fontforge
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 869614.
In Mitre's CVE dictionary: CVE-2017-11568, CVE-2017-11569, CVE-2017-11571, CVE-2017-11572, CVE-2017-11574, CVE-2017-11575, CVE-2017-11576, CVE-2017-11577.
More information:

It was discovered that FontForge, a font editor, did not correctly validate its input. An attacker could use this flaw by tricking a user into opening a maliciously crafted OpenType font file, thus causing a denial-of-service via application crash, or execution of arbitrary code.

For the oldstable distribution (jessie), these problems have been fixed in version 20120731.b-5+deb8u1.

For the stable distribution (stretch), these problems have been fixed in version 1:20161005~dfsg-4+deb9u1.

We recommend that you upgrade your fontforge packages.