FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesave.c. Upstream Issue: https://github.com/fontforge/fontforge/issues/4085
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-5496