-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: fontforge security update
Advisory ID:       RHSA-2020:4844-01
Product:           Red Hat Enterprise Linux
Advisory URL:      https://access.redhat.com/errata/RHSA-2020:4844
Issue date:        2020-11-03
CVE Names:         CVE-2020-25690 
====================================================================
1. Summary:

An update for fontforge is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat CodeReady Linux Builder (v. 8) - aarch64, ppc64le, s390x, x86_64

3. Description:

FontForge is a font editor for outline and bitmap fonts. It supports a
range of font formats, including PostScript (ASCII and binary Type 1, some
Type 3 and Type 0), TrueType, OpenType (Type2) and CID-keyed fonts. 

Security Fix(es):

* fontforge: SFD_GetFontMetaData() insufficient CVE-2020-5395 backport
(CVE-2020-25690)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat
Enterprise Linux 8.3 Release Notes linked from the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1893188 - CVE-2020-25690 fontforge: SFD_GetFontMetaData() insufficient CVE-2020-5395 backport

6. Package List:

Red Hat CodeReady Linux Builder (v. 8):

Source:
fontforge-20170731-15.el8.src.rpm

aarch64:
fontforge-20170731-15.el8.aarch64.rpm
fontforge-debuginfo-20170731-15.el8.aarch64.rpm
fontforge-debugsource-20170731-15.el8.aarch64.rpm

ppc64le:
fontforge-20170731-15.el8.ppc64le.rpm
fontforge-debuginfo-20170731-15.el8.ppc64le.rpm
fontforge-debugsource-20170731-15.el8.ppc64le.rpm

s390x:
fontforge-20170731-15.el8.s390x.rpm
fontforge-debuginfo-20170731-15.el8.s390x.rpm
fontforge-debugsource-20170731-15.el8.s390x.rpm

x86_64:
fontforge-20170731-15.el8.i686.rpm
fontforge-20170731-15.el8.x86_64.rpm
fontforge-debuginfo-20170731-15.el8.i686.rpm
fontforge-debuginfo-20170731-15.el8.x86_64.rpm
fontforge-debugsource-20170731-15.el8.i686.rpm
fontforge-debugsource-20170731-15.el8.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2020-25690
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.3_release_notes/

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBX6I32NzjgjWX9erEAQjYPA//UUYbPez9RLTPbahbnt6aZq0dMVPLHSXI
jFBYOz+NUa/WTDc7rl5F1RK18cCnl2LKP1sr7UjxMT4gOgnxQQXT1EbHrnEqP5Iz
EKyF9pZxv3g2D+OsIVli+imM4j+3/44qYCeSieBnS4S0XpK7Tyb4goFmi0sQiTKK
jt/QnadiYrQsAF2syis9rkmWjq1oP5cCMT8Ift4pgpCBoS8u3Jg9/pNB8tkLsi4B
xouhxlkKo4ikork/5hE5bQLvlgoXCg9AX9HfMk2Pag3HKxCRGZYIHQbUXFYheXTJ
MiwUrE7NB9zOsCinsZccgtcFB2APHNBYcYXtA8/x4z+Db9h1tcDmzf1X9Ysl9CSy
w2UJWxdwYjU7yQvGUXcOOZd9/zcEsQGK9WpkQWTCOsnnF7iDG3TfFZwH4KvFEEjL
FGBohr2qsl6RZAHjd9k5q+2URt0Vh9Bdg8Pu7nO1tP1Ek63FlqjmMUiSDTe7w2Uu
7twzXIJba2FqU5k3GdoqCzQmYM9h7QqBufCnNae+zmJFHBK4elkQwk+bqNObEItQ
8jFvI8TkZZmu+g+MBopO4L6ioGpL5GQzaaIA8NkbyP12UF1VW0IOMmZK74zJ+PXa
k2A9sCcwCVatG1rOrq9EKJsdWpolxc+MduYIIHVOpZxTBVH7I1+qZAGfWACIMw6t
5CbBplqsemo=yS9R
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2020-4844:01 Moderate: fontforge security update

An update for fontforge is now available for Red Hat Enterprise Linux 8

Summary

FontForge is a font editor for outline and bitmap fonts. It supports a range of font formats, including PostScript (ASCII and binary Type 1, some Type 3 and Type 0), TrueType, OpenType (Type2) and CID-keyed fonts.
Security Fix(es):
* fontforge: SFD_GetFontMetaData() insufficient CVE-2020-5395 backport (CVE-2020-25690)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2020-25690 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.3_release_notes/

Package List

Red Hat CodeReady Linux Builder (v. 8):
Source: fontforge-20170731-15.el8.src.rpm
aarch64: fontforge-20170731-15.el8.aarch64.rpm fontforge-debuginfo-20170731-15.el8.aarch64.rpm fontforge-debugsource-20170731-15.el8.aarch64.rpm
ppc64le: fontforge-20170731-15.el8.ppc64le.rpm fontforge-debuginfo-20170731-15.el8.ppc64le.rpm fontforge-debugsource-20170731-15.el8.ppc64le.rpm
s390x: fontforge-20170731-15.el8.s390x.rpm fontforge-debuginfo-20170731-15.el8.s390x.rpm fontforge-debugsource-20170731-15.el8.s390x.rpm
x86_64: fontforge-20170731-15.el8.i686.rpm fontforge-20170731-15.el8.x86_64.rpm fontforge-debuginfo-20170731-15.el8.i686.rpm fontforge-debuginfo-20170731-15.el8.x86_64.rpm fontforge-debugsource-20170731-15.el8.i686.rpm fontforge-debugsource-20170731-15.el8.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2020:4844-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2020:4844
Issued Date: : 2020-11-03
CVE Names: CVE-2020-25690

Topic

An update for fontforge is now available for Red Hat Enterprise Linux 8.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat CodeReady Linux Builder (v. 8) - aarch64, ppc64le, s390x, x86_64


Bugs Fixed

1893188 - CVE-2020-25690 fontforge: SFD_GetFontMetaData() insufficient CVE-2020-5395 backport


Related News