REDHAT-BUG-2266180: Command Injection
Published Feb 26, 2024
·Updated
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
https://github.com/fontforge/fontforge/pull/5367
Affected Software
1 affected component
FontForge Splinefont<=20230101
Event History
Feb 26, 2024
Data Sourced
via Red Hat·09:38 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2266180?
REDHAT-BUG-2266180 is classified as a critical vulnerability due to its potential for command injection.
2
How do I fix REDHAT-BUG-2266180?
To fix REDHAT-BUG-2266180, update FontForge Splinefont to a version later than 20230101.
3
What type of vulnerability is REDHAT-BUG-2266180?
REDHAT-BUG-2266180 is a command injection vulnerability that can be exploited through crafted archives or compressed files.
4
Which versions are affected by REDHAT-BUG-2266180?
REDHAT-BUG-2266180 affects FontForge Splinefont versions up to and including 20230101.
5
Is there an exploit available for REDHAT-BUG-2266180?
While specific exploit details are not provided, the nature of the vulnerability suggests that it can be exploited with specially crafted files.