﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
13488	fontforge-20200314	ken@…	ken@…	"I just noticed gentoo have issued a security alert for fontforge, 

CVE-2019-15785 [https://nvd.nist.gov/vuln/detail/CVE-2019-15785]

CVE-2020-5395 [https://nvd.nist.gov/vuln/detail/CVE-2020-5395]

CVE-2020-5496 [https://nvd.nist.gov/vuln/detail/CVE-2020-5496]

and report that all are fixed in 20200314.

The first is rated as Critical, the other two as High. Gentoo describe the impact as:

A remote attacker could entice a user to open a specially crafted font
using FontForge, possibly resulting in execution of arbitrary code with
the privileges of the process or a Denial of Service condition.

But perhaps more significant for us, we seem to be stuck on 20170731.
"	defect	closed	high	10.0	BOOK	SVN	medium	fixed		
