High severity8.8NVD Advisory· Published Jan 3, 2020· Updated Jun 17, 2026
CVE-2020-5395
CVE-2020-5395
Description
FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- FontForge/FontForgedescription
- osv-coords5 versionspkg:rpm/almalinux/fontforgepkg:rpm/opensuse/fontforge&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/fontforge&distro=openSUSE%20Tumbleweedpkg:rpm/suse/fontforge&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/fontforge&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
< 20170731-15.el8+ 4 more
- (no CPE)range: < 20170731-15.el8
- (no CPE)range: < 20170731-lp151.4.3.1
- (no CPE)range: < 20201107-1.6
- (no CPE)range: < 20170731-11.11.1
- (no CPE)range: < 20170731-11.11.1
Patches
Vulnerability mechanics
References
6- github.com/fontforge/fontforge/issues/4084nvdExploitPatchThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-01/msg00041.htmlnvdThird Party Advisory
- security.gentoo.org/glsa/202004-14nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2024/03/msg00007.htmlnvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2S75EAVF4KPCH3WFBMZADUAU7EAXA7ZQ/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MH6PKVQLBKIO7LQPDXB3MKI5I6AMDCN6/nvd
News mentions
0No linked articles in our index yet.