Updated fontforge packages fix security vulnerabilities
Publication date: 28 Jan 2020Modification date: 28 Jan 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-5395 , CVE-2020-5496
Description
FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c (CVE-2020-5395) FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesave.c (CVE-2020-5496)
References
SRPMS
7/core
- fontforge-20190413-1.1.mga7