A funny infosec thread is unwinding right now in FontForge.
Some company published 12 CVEs on a dormant (over 10 years!) SourceForge account, and they were of course promptly ignored.
Half year later they made 4 of them public and finally reached us at GitHub, where these advisories were ignored once again, this time explicitly. https://github.com/fontforge/fontforge/issues/5706
1/🧵




















