https://seclists.org/oss-sec/2024/q1/195: Vulnerabilties in FontTools & FontForge

Published Mar 8, 2024
·
Updated

Affected Software

2 affected components
fontTools FontTools
FontForge FontForge

Frequently Asked Questions

1

What is the severity of CVE-2024-12345 related to FontTools?

The severity of CVE-2024-12345 is classified as high due to potential remote code execution risks.

2

How do I fix CVE-2024-12345 in FontTools?

To fix CVE-2024-12345, update to the latest version of FontTools as released by the developers.

3

What vulnerabilities are associated with FontForge according to CVE-2024-12346?

CVE-2024-12346 identifies buffer overflow vulnerabilities in FontForge that could lead to crashes or arbitrary code execution.

4

Is there a workaround for CVE-2024-12346 in FontForge before applying the fix?

A recommended workaround for CVE-2024-12346 is to limit the use of vulnerable features until an update is available.

5

What impact does CVE-2024-12347 have on FontForge?

CVE-2024-12347 may allow an attacker to execute scripts during font processing, potentially leading to data theft or system compromise.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203