Vulnerability Bulletins

DSA-3958 fontforge - security update

   
Affected software Debian
 
It was discovered that FontForge, a font editor, did not correctlyvalidate its input. An attacker could use this flaw by tricking a userinto opening a maliciously crafted OpenType font file, thus causing adenial-of-service via application crash, or execution of arbitrarycode.

More info:

https://www.debian.org/security/2017/dsa-3958