Skip to content
Commit 4d5e37e0 authored by Salvatore Bonaccorso's avatar Salvatore Bonaccorso
Browse files

Update information on CVE-2019-19847/libspiro

The issue is actually in an exported function, spiro_to_bpath0, but it's
not in the 'advertised' API. Cf.
https://github.com/fontforge/libspiro/issues/21#issuecomment-567983822 .
But no users seem present of the respective problematic function and as
such opted to mark it with negligible impact.

Safer might be to actually revert this, and mark it no-dsa.
parent c109178d
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment