CVE-2015-3905: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 6.9% chance of exploitation in the next 30 days.
Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.39 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 14.10 only
- t1utils Project t1utils: version 1.38 only
Published 2015-06-08. Last modified 2026-06-17.