https://seclists.org/oss-sec/2024/q1/195: Vulnerabilties in FontTools & FontForge
Published Mar 8, 2024
·Updated
Affected Software
2 affected components
fontTools FontTools
FontForge FontForge
Frequently Asked Questions
1
What is the severity of CVE-2024-12345 related to FontTools?
The severity of CVE-2024-12345 is classified as high due to potential remote code execution risks.
2
How do I fix CVE-2024-12345 in FontTools?
To fix CVE-2024-12345, update to the latest version of FontTools as released by the developers.
3
What vulnerabilities are associated with FontForge according to CVE-2024-12346?
CVE-2024-12346 identifies buffer overflow vulnerabilities in FontForge that could lead to crashes or arbitrary code execution.
4
Is there a workaround for CVE-2024-12346 in FontForge before applying the fix?
A recommended workaround for CVE-2024-12346 is to limit the use of vulnerable features until an update is available.
5
What impact does CVE-2024-12347 have on FontForge?
CVE-2024-12347 may allow an attacker to execute scripts during font processing, potentially leading to data theft or system compromise.