Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 9: 2024-0082 Critical: FontForge Command Injection Risks

mageia
Calendar Grey March 22, 2024
Dist Mageia Esm H88
New FontForge releases strengthen defenses against command injection threats, resolving two significant vulnerabilities identified in Mageia.
Splinefont in FontForge through 20230101 allows command injection via crafted filenames

Summary

Splinefont in FontForge through 20230101 allows command injection via crafted filenames. (CVE-2024-25081) Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files. (CVE-2024-25082)

References

- https://bugs.mageia.org/show_bug.cgi?id=32956

- https://www.openwall.com/lists/oss-security/2024/03/08/2

- https://github.com/advisories/GHSA-rjx3-xwwm-jhj5

- https://github.com/advisories/GHSA-2j3h-j2q3-wxp3

- https://www.cve.org/CVERecord?id=CVE-2024-25081

- https://www.cve.org/CVERecord?id=CVE-2024-25082

Resolution

SRPMS

- 9/core/fontforge-20220308-2.1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 22 Mar 2024
URL: https://advisories.mageia.org/MGASA-2024-0082.html
Type: security
CVE: CVE-2024-25081, CVE-2024-25082

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here