https://bugzilla.redhat.com/show_bug.cgi?id=1751048
Bug ID: 1751048 Summary: CVE-2019-15785 fontforge: buffer overflow in PrefsUI_LoadPrefs in prefs.c Product: Security Response Hardware: All OS: Linux Status: NEW Component: vulnerability Keywords: Security Severity: medium Priority: medium Assignee: security-response-team@redhat.com Reporter: darunesh@redhat.com CC: eng-i18n-bugs@redhat.com, fonts-bugs@lists.fedoraproject.org, kevin@scrye.com, paul@frixxon.co.uk, pnemade@redhat.com Target Milestone: --- Classification: Other
A vulnerability was found in FontForge through 20190801 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.
Reference: https://github.com/fontforge/fontforge/pull/3886
https://bugzilla.redhat.com/show_bug.cgi?id=1751048
Dhananjay Arunesh darunesh@redhat.com changed:
What |Removed |Added ---------------------------------------------------------------------------- Depends On| |1751050
--- Comment #1 from Dhananjay Arunesh darunesh@redhat.com --- Created fontforge tracking bugs for this issue:
Affects: fedora-all [bug 1751050]
Referenced Bugs:
https://bugzilla.redhat.com/show_bug.cgi?id=1751050 [Bug 1751050] CVE-2019-15785 fontforge: buffer overflow in PrefsUI_LoadPrefs in prefs.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1751048
Dhananjay Arunesh darunesh@redhat.com changed:
What |Removed |Added ---------------------------------------------------------------------------- Blocks| |1751051
https://bugzilla.redhat.com/show_bug.cgi?id=1751048
Parag Nemade pnemade@redhat.com changed:
What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |ASSIGNED
https://bugzilla.redhat.com/show_bug.cgi?id=1751048
Parag Nemade pnemade@redhat.com changed:
What |Removed |Added ---------------------------------------------------------------------------- Status|ASSIGNED |CLOSED Resolution|--- |NOTABUG Last Closed| |2019-09-18 11:23:43
--- Comment #2 from Parag Nemade pnemade@redhat.com --- Please note there is no upstream release that includes the initial commit https://github.com/fontforge/fontforge/commit/626f751752875a0ddd74b9e217b6f4... that added warn_script_unsaved to fontview.c and prefs.c files. Then how come this CVE got reported against Fedora 30?
https://bugzilla.redhat.com/show_bug.cgi?id=1751048 Bug 1751048 depends on bug 1751050, which changed state.
Bug 1751050 Summary: CVE-2019-15785 fontforge: buffer overflow in PrefsUI_LoadPrefs in prefs.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1751050
What |Removed |Added ---------------------------------------------------------------------------- Status|ASSIGNED |CLOSED Resolution|--- |NOTABUG
https://bugzilla.redhat.com/show_bug.cgi?id=1751048
Marco Benatto mbenatto@redhat.com changed:
What |Removed |Added ---------------------------------------------------------------------------- Status|CLOSED |NEW Resolution|NOTABUG |--- Keywords| |Reopened
https://bugzilla.redhat.com/show_bug.cgi?id=1751048
Marco Benatto mbenatto@redhat.com changed:
What |Removed |Added ---------------------------------------------------------------------------- Priority|medium |low Severity|medium |low
https://bugzilla.redhat.com/show_bug.cgi?id=1751048
--- Comment #4 from Marco Benatto mbenatto@redhat.com --- Statement:
The versions of fontforge package shipped with Red Hat Enterprise Linux 5, 6, 7 and 8 are not affected by this issue as it doesn't contain the code where the vulnerability resides.
https://bugzilla.redhat.com/show_bug.cgi?id=1751048
Marco Benatto mbenatto@redhat.com changed:
What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |CLOSED Resolution|--- |NOTABUG Last Closed|2019-09-18 11:23:43 |2019-09-19 20:03:06
fonts-bugs@lists.fedoraproject.org