CVE-2015-3905
t1utils - security update
EPSS 6.9%
Description
Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.39 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
How to fix CVE-2015-3905
To remediate CVE-2015-3905, upgrade the affected package to a fixed version below.
- Debian/t1utils—upgrade to 1.38-4 or later
- Debian/t1utils—upgrade to 1.36-1+deb6u1 or later
Is CVE-2015-3905 being exploited?
Moderate — EPSS is 6.9%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 1.38-4
- from 0, < 1.36-1+deb6u1