FontForge.BDF.Font.File.Stack.Buffer.Overflow

description-logoDescription

This indicates an attack attempt against an Stack Overflow vulnerability in FontForge.
The vulnerability is caused by an error when handling malformed "BDF" file. It allows a remote attacker to execute arbitrary code by sending a crafted "BDF" file.

affected-products-logoAffected Products

Red Hat Fedora 14
Red Hat Fedora 13
Red Hat Enterprise Linux 6
Gentoo Linux
FontForge FontForge 0.0.20100501-2
Debian Linux 5.0 sparc
Debian Linux 5.0 s/390
Debian Linux 5.0 powerpc
Debian Linux 5.0 mipsel
Debian Linux 5.0 mips
Debian Linux 5.0 m68k
Debian Linux 5.0 ia-64
Debian Linux 5.0 ia-32
Debian Linux 5.0 hppa
Debian Linux 5.0 armel
Debian Linux 5.0 arm
Debian Linux 5.0 amd64
Debian Linux 5.0 alpha
Debian Linux 5.0

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Refer to the vendor's web site for suggested workaround.
http://fontforge.sourceforge.net/

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)