OESA-2024-1080

    Dashboard / Vulnerabilities / OESA-2024-1080

    OESA-2024-1080

    Published: 19 Jan 2024Last Modified: 18 Aug 2026
    Upstream:

    Summary: python-fonttools security update

    Details: FontTools is a library for manipulating fonts, written in Python. The project includes the TTX tool, that can convert TrueType and OpenType fonts to and from an XML text format, which is also called TTX. It supports TrueType, OpenType, AFM and to an extent Type 1 and some Mac-specific formats. The project has an MIT open-source licence. Security Fix(es): fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker to resolve arbitrary entities when a candidate font (OT-SVG fonts), which contains a SVG table, is parsed. This allows attackers to include arbitrary files from the filesystem fontTools is running on or make web requests from the host system. This vulnerability has been patched in version 4.43.0.(CVE-2023-45139)

    Affected packages

    Package

    Name: python-fonttools

    Purl: pkg:rpm/openEuler/python-fonttools&distro=openEuler-22.03-LTS-SP3

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -fonttools-4.39.4-2.oe2203sp3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    OESA-2024-1080 | CVE-DB