CVE Vulnerabilities

CVE-2024-25082

Published: Feb 26, 2024 | Modified: May 01, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
4.2 MODERATE
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
Ubuntu
MEDIUM

Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.

Affected Software

Name Vendor Start Version End Version
Red Hat Enterprise Linux 8 RedHat fontforge-0:20200314-6.el8_10 *
Fontforge Ubuntu bionic *
Fontforge Ubuntu esm-apps/bionic *
Fontforge Ubuntu esm-apps/xenial *
Fontforge Ubuntu focal *
Fontforge Ubuntu jammy *
Fontforge Ubuntu mantic *
Fontforge Ubuntu trusty *
Fontforge Ubuntu upstream *
Fontforge Ubuntu xenial *

References