FontForge
cpe:2.3:a:fontforge:fontforge:*:*:*:*:*:*:*, +1 more
A remote code execution vulnerability has been identified in FontForge, specifically within the SFD file parsing process. This issue arises from improper validation of user-supplied data, allowing for a write past the end of an allocated array. As a result, remote attackers can execute arbitrary code on affected installations, but user interaction is required to exploit the vulnerability by opening a malicious SFD file.
Exploitation of this vulnerability allows for arbitrary code execution on the affected system, executed in the context of the current user.
Due to the nature of this vulnerability, the recommended mitigation strategy is to limit interaction with the product.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.