EPSS
Percentile
39.5%
libfontforge.so is vulnerable to remote code execution (RCE0 attacks. A malicious user can pass a ttf file to the application to cause a buffer overread that can crash the application or allow arbitrary code to be executed.
ttf
www.debian.org/security/2017/dsa-3958
github.com/fontforge/fontforge/commit/b3b773789409586de47da56f644a4568bafa8ec4
github.com/fontforge/fontforge/issues/3092