Update information on CVE-2019-19847/libspiro
The issue is actually in an exported function, spiro_to_bpath0, but it's not in the 'advertised' API. Cf. https://github.com/fontforge/libspiro/issues/21#issuecomment-567983822 . But no users seem present of the respective problematic function and as such opted to mark it with negligible impact. Safer might be to actually revert this, and mark it no-dsa.
Loading
Please register or sign in to comment