FontForge
cpe:2.3:a:fontforge:fontforge:*:*:*:*:*:*:*, +1 more
- <= 20230101
A memory leak vulnerability has been identified in FontForge versions through 20230101. The issue arises in the utf7toutf8_copy function, leading to a denial-of-service condition by causing unnecessary memory consumption.
Exploitation of this vulnerability causes a memory leak, which can lead to increased memory usage and potential denial-of-service conditions.
The vulnerability can be reproduced by compiling FontForge with leak sanitization enabled, using specific compiler flags. After compiling and installing the application, the memory leak can be triggered by executing FontForge with a command that opens a specially crafted file, which can be referenced as 'poc_file'.
Users can upgrade to the latest version of FontForge, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.