Gnome Fonts Viewer 3.34.0 Heap Corruption
Vulnerability Description
Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger an out-of-bounds write by crafting a malicious TTF font file. Attackers can generate a specially crafted TTF file with an oversized pattern to exhaust memory through repeated malloc() calls and potentially crash the gnome-font-viewer process.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-37011
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Cody Winkler
References
More from GNOME
View All →Affected Vendor
GNOME
View all reports →