Advisories ยป MGASA-2020-0057

Updated fontforge packages fix security vulnerabilities

Publication date: 28 Jan 2020
Modification date: 28 Jan 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-5395 , CVE-2020-5496

Description

FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c
(CVE-2020-5395)

FontForge 20190801 has a heap-based buffer overflow in the
Type2NotDefSplines() function in splinesave.c (CVE-2020-5496)
                

References

SRPMS

7/core