Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6408
HistoryMay 28, 2018 - 10:12 a.m.

Remote Code Execution (RCE)

2018-05-2810:12:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

EPSS

0.001

Percentile

39.5%

libfontforge.so is vulnerable to remote code execution (RCE) attacks. A malicious user can pass an otf file to the PSCharStringToSplines function in psread.c to cause a buffer overflow that can crash the application or cause arbitrary code execution.