OESA-2024-1228
Dashboard / Vulnerabilities / OESA-2024-1228
Summary: fontforge security update
Details: FontForge (former PfaEdit) is a font editor for outline and bitmap fonts. It supports a range of font formats, including PostScript (ASCII and binary Type 1, some Type 3 and Type 0), TrueType, OpenType (Type2) and CID-keyed fonts. Security Fix(es): Splinefont in FontForge through 20230101 allows command injection via crafted filenames.(CVE-2024-25081) Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.(CVE-2024-25082)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2024-1228, https://nvd.nist.gov/vuln/detail/CVE-2024-25081, https://nvd.nist.gov/vuln/detail/CVE-2024-25082
Affected packages
Package
Name: fontforge
Purl: pkg:rpm/openEuler/fontforge&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
