TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Font Parsing Vulnerabilities

32 pointsby Jahakalmost 10 years ago

3 comments

tlbalmost 10 years ago
I worked on font parsing at one point. Indeed, the font rendering libraries are fragile and the formats complex and poorly documented.<p>This is a case of something being initially designed without security in mind, because fonts were something you bought and installed on your computer like applications. Suddenly, fonts were being automatically downloaded and rendered on web pages.<p>Auditing font libraries is hard, because you need combined expertise in security and font rendering (which is deeply intricate, especially with full non-Western writing system support.) I expect to see more vulnerabilities here.
评论 #9888216 未加载
gurgeousalmost 10 years ago
Do these vulnerabilities suggest that attackers can gain access to your machine by sending an evil font to your browser? I wish this was getting more press&#x2F;discussion.
评论 #9886592 未加载
nfozalmost 10 years ago
Browser vendors &#x2F; web standards continue to expand the set of functionality that a browser provides. Each time they do so, they increase the attack surface.