Questions tagged [font]

Use for question about security risks associated with fonts, such as OTF or TTF-files.

3 questions
12
votes
1 answer

How to detect suspicious content in a TrueType Font (.ttf) font file

I got curious about how to scan or assess the risk of a particular font file before deploying it to hosts. First line of defense, of course, is to make sure that our hosts are patched against any TrueType font vulnerabilities. I read the excellent…
mcgyver5
  • 6,807
  • 2
  • 24
  • 45
11
votes
1 answer

How do I know if a font is malicious?

There are cases of fonts being used for exploiting vulnerabilities (for ex: ThreatPost, SecureList and F-Secure). My question is if you ever get hands on such a font, how do you know that it is malicious?
TheRookierLearner
  • 4,222
  • 8
  • 24
  • 28
1
vote
1 answer

Font risk in unopened email in inbox

This is obviously not from PayPal, but the font in the word account displayed using odd looking font, is this a security risk to me that Outlook.com displayed this font? See below, Outlook has preview text enabled as default
Coderxyz
  • 562
  • 4
  • 9