Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

Mageia 9: 2024-0060 Critical: FontTools XXE Injection Attack

mageia
Calendar Grey March 14, 2024
Dist Mageia Esm H88
Revised fonttools libraries in Mageia address security concerns linked to XXE vulnerability present in OT-SVG typefaces.
As of fonttools>=4.28.2 the subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker to resolve arbitrary entities when a candidate font (...

Summary

As of fonttools>=4.28.2 the subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker to resolve arbitrary entities when a candidate font (OT-SVG fonts), which contains a SVG table, is parsed. This allows attackers to include arbitrary files from the filesystem fontTools is running on or make web requests from the host system.

References

- https://bugs.mageia.org/show_bug.cgi?id=32955

- https://www.openwall.com/lists/oss-security/2024/03/08/2

- https://github.com/fonttools/fonttools/security/advisories/GHSA-6673-4983-2vx5

- https://www.cve.org/CVERecord?id=CVE-2023-45139

Resolution

SRPMS

- 9/core/fonttools-4.38.0-2.1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 14 Mar 2024
URL: https://advisories.mageia.org/MGASA-2024-0060.html
Type: security
CVE: CVE-2023-45139

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here