Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6401
HistoryMay 28, 2018 - 7:31 a.m.

Remote Code Execution (RCE) Through Buffer Overread

2018-05-2807:31:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

EPSS

0.001

Percentile

39.5%

libfontforge.so is vulnerable to remote code execution (RCE0 attacks. A malicious user can pass a ttf file to the application to cause a buffer overread that can crash the application or allow arbitrary code to be executed.