
Cloud Vulnerability DB
A community-led vulnerabilities database
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6b04de. This vulnerability was assigned CVE-2022-35447 and was disclosed in August 2022 (NVD).
The vulnerability is a heap-based buffer overflow that occurs in the otfccdump component. The issue manifests when processing certain input files, specifically at memory location /release-x64/otfccdump+0x6b04de (Debian Security).
The heap buffer overflow vulnerability could potentially lead to memory corruption and program crashes. The issue affects the functionality of the OTFCC tool when processing certain font files.
The vulnerability has been fixed in updated versions of the software. Debian has addressed this in various distributions, with fixes implemented in bullseye (2020.20200327.54578-7+deb11u2) while some versions remain vulnerable including bookworm, trixie, and sid (Debian Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."