USN-6856-1: FontForge vulnerabilities
It was discovered that FontForge incorrectly handled filenames. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to perform a command injection. (CVE-2024-25081) It was discovered that FontForge incorrectly handled archives and compressed files. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to perform command injection. (CVE-2024-25082)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6856-1?
The severity of USN-6856-1 is considered high due to the potential for command injection vulnerabilities.
How do I fix USN-6856-1?
To fix USN-6856-1, update your FontForge and python3-fontforge packages to the recommended versions provided by Ubuntu.
Which versions of FontForge are affected by USN-6856-1?
USN-6856-1 affects multiple versions of FontForge across Ubuntu 16.04, 18.04, 20.04, 22.04, and 23.10.
Can USN-6856-1 lead to remote attacks?
Yes, USN-6856-1 can allow remote attackers to potentially execute commands if a specially crafted input file is opened.
Is USN-6856-1 applicable to all Ubuntu users?
USN-6856-1 is relevant for users of Ubuntu versions 16.04, 18.04, 20.04, 22.04, and 23.10 using affected FontForge packages.