CVE-2024-25082: Command Injection
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/fontforgeto a version that resolves this vulnerability.Fixed in 1:20170731~dfsg-1ubuntu0.1~ - Upgrade
Upgrade
ubuntu/fontforgeto a version that resolves this vulnerability.Fixed in 1:20190801~dfsg-4ubuntu0.1 - Upgrade
Upgrade
ubuntu/fontforgeto a version that resolves this vulnerability.Fixed in 1:20201107~dfsg-4+ - Upgrade
Upgrade
ubuntu/fontforgeto a version that resolves this vulnerability.Fixed in 1:20230101~dfsg-1ubuntu0.1 - Upgrade
Upgrade
ubuntu/fontforgeto a version that resolves this vulnerability.Fixed in 20120731. - Upgrade
Upgrade
debian/fontforgeto a version that resolves this vulnerability.Fixed in 1:20201107~dfsg-4+deb11u1Fixed in 1:20230101~dfsg-1.1~deb12u1Fixed in 1:20230101~dfsg-3
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25082?
CVE-2024-25082 has a high severity due to the potential for command injection.
How do I fix CVE-2024-25082?
To fix CVE-2024-25082, upgrade to a patched version of FontForge specified for your distribution.
What versions of FontForge are affected by CVE-2024-25082?
Versions of FontForge prior to 20230101 on various Ubuntu and Debian distributions are affected by CVE-2024-25082.
What types of files can trigger the vulnerability in CVE-2024-25082?
CVE-2024-25082 can be triggered via crafted archives or compressed files.
Is CVE-2024-25082 exploit-related?
Yes, CVE-2024-25082 is related to a vulnerability that allows attackers to execute arbitrary commands through exploited files.