CVE-2024-25082
published 2024-02-26CVE-2024-25082: Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
PriorityP344medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
1.87%
77.0th percentile
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | fontforge | < fontforge 1:20230101~dfsg-1.1~deb12u1 (bookworm) | fontforge 1:20230101~dfsg-1.1~deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fontforge | fontforge | <= 20230101 | — |
| fontforge | fontforge | >= 0 < 1:20201107~dfsg-4+deb11u1 | 1:20201107~dfsg-4+deb11u1 |
| fontforge | fontforge | >= 0 < 1:20230101~dfsg-1.1~deb12u1 | 1:20230101~dfsg-1.1~deb12u1 |
| fontforge | fontforge | >= 0 < 1:20230101~dfsg-1.1 | 1:20230101~dfsg-1.1 |
| fontforge | fontforge | >= 0 < 1:20230101~dfsg-1.1 | 1:20230101~dfsg-1.1 |
| fontforge | fontforge | >= 0 < 1:20190801~dfsg-4ubuntu0.1 | 1:20190801~dfsg-4ubuntu0.1 |
| fontforge | fontforge | >= 0 < 1:20201107~dfsg-4+deb11u1build0.22.04.1 | 1:20201107~dfsg-4+deb11u1build0.22.04.1 |
| fontforge | fontforge | >= 0 < 20120731.b-7.1ubuntu0.1+esm1 | 20120731.b-7.1ubuntu0.1+esm1 |
| fontforge | fontforge | >= 0 < 1:20170731~dfsg-1ubuntu0.1~esm1 | 1:20170731~dfsg-1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
fontforge vulnerabilities
osv·2024-06-27·CVSS 4.2
CVE-2024-25081 [MEDIUM] fontforge vulnerabilities
fontforge vulnerabilities
It was discovered that FontForge incorrectly handled filenames. If a user or an
automated system were tricked into opening a specially crafted input file, a
remote attacker could possibly use this issue to perform a command injection.
(CVE-2024-25081)
It was discovered that FontForge incorrectly handled archives and compressed
files. If a user or an automated system were tricked into opening a specially
crafted input file, a remote attacker could possibly use this issue to perform
command injection. (CVE-2024-25082)
GHSA
GHSA-2j3h-j2q3-wxp3: Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files
ghsa_unreviewed·2024-02-26
CVE-2024-25082 [MEDIUM] CWE-77 GHSA-2j3h-j2q3-wxp3: Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
OSV
CVE-2024-25082: Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files
osv·2024-02-26·CVSS 6.5
CVE-2024-25082 [MEDIUM] CVE-2024-25082: Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
Ubuntu
FontForge vulnerabilities
vendor_ubuntu·2024-06-27·CVSS 4.2
CVE-2024-25082 [MEDIUM] FontForge vulnerabilities
Title: FontForge vulnerabilities
Summary: Several security issues were fixed in FontForge.
It was discovered that FontForge incorrectly handled filenames. If a user or an
automated system were tricked into opening a specially crafted input file, a
remote attacker could possibly use this issue to perform a command injection.
(CVE-2024-25081)
It was discovered that FontForge incorrectly handled archives and compressed
files. If a user or an automated system were tricked into opening a specially
crafted input file, a remote attacker could possibly use this issue to perform
command injection. (CVE-2024-25082)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
fontforge: command injection via crafted archives or compressed files
vendor_redhat·2024-02-26·CVSS 6.5
CVE-2024-25082 [MEDIUM] CWE-78 fontforge: command injection via crafted archives or compressed files
fontforge: command injection via crafted archives or compressed files
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
Package: fontforge (Red Hat Enterprise Linux 6) - Out of support scope
Package: fontforge (Red Hat Enterprise Linux 7) - Out of support scope
Debian
CVE-2024-25082: fontforge - Splinefont in FontForge through 20230101 allows command injection via crafted ar...
vendor_debian·2024·CVSS 6.5
CVE-2024-25082 [MEDIUM] CVE-2024-25082: fontforge - Splinefont in FontForge through 20230101 allows command injection via crafted ar...
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
Scope: local
bookworm: resolved (fixed in 1:20230101~dfsg-1.1~deb12u1)
bullseye: resolved (fixed in 1:20201107~dfsg-4+deb11u1)
forky: resolved (fixed in 1:20230101~dfsg-1.1)
sid: resolved (fixed in 1:20230101~dfsg-1.1)
trixie: resolved (fixed in 1:20230101~dfsg-1.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2024/03/08/2https://fontforge.org/en-US/downloads/https://github.com/fontforge/fontforge/pull/5367https://lists.debian.org/debian-lts-announce/2024/03/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GCH22HIO2C6M4BZWF5EYIWVFBXL5BQAH/http://www.openwall.com/lists/oss-security/2024/03/08/2https://fontforge.org/en-US/downloads/https://github.com/fontforge/fontforge/pull/5367https://lists.debian.org/debian-lts-announce/2024/03/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GCH22HIO2C6M4BZWF5EYIWVFBXL5BQAH/https://lists.fedoraproject.org/archives/list/[email protected]/message/GCH22HIO2C6M4BZWF5EYIWVFBXL5BQAH/
2024-02-26
Published