REDHAT-BUG-2266181: Command Injection
Published Feb 26, 2024
·Updated
Splinefont in FontForge through 20230101 allows command injection via crafted filenames.
https://github.com/fontforge/fontforge/pull/5367
Affected Software
1 affected component
FontForge FontForge>=20230101
Event History
Feb 26, 2024
Data Sourced
via Red Hat·09:38 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2266181?
The severity of REDHAT-BUG-2266181 is classified as critical due to the potential for command injection.
2
How do I fix REDHAT-BUG-2266181?
To fix REDHAT-BUG-2266181, update FontForge to a version later than 20230101 that addresses the command injection issue.
3
What versions of FontForge are affected by REDHAT-BUG-2266181?
FontForge versions from 20230101 and earlier are affected by REDHAT-BUG-2266181.
4
What is the impact of REDHAT-BUG-2266181?
The impact of REDHAT-BUG-2266181 includes the potential for attackers to execute arbitrary commands on the system via crafted filenames.
5
How can I determine if my system is vulnerable to REDHAT-BUG-2266181?
To determine vulnerability to REDHAT-BUG-2266181, check if you're running FontForge version 20230101 or earlier.