8.8
CVSSv3

CVE-2020-5496

Published: 03/01/2020 Updated: 08/03/2024
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesave.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fontforge fontforge 20190801

opensuse leap 15.1

Vendor Advisories

Debian Bug report logs - #948231 fontforge: CVE-2020-5395 CVE-2020-5496 Package: fontforge; Maintainer for fontforge is Debian Fonts Task Force <pkg-fonts-devel@listsaliothdebianorg>; Source for fontforge is src:fontforge (PTS, buildd, popcon) Reported by: Markus Koschany <apo@debianorg> Date: Sun, 5 Jan 2020 17 ...