ALAS-2024-565


Amazon Linux 2023 Security Advisory: ALAS-2024-565
Advisory Release Date: 2024-03-13 20:41 Pacific
Advisory Updated Date: 2024-03-21 14:00 Pacific
Severity: Medium

Issue Overview:

Splinefont in FontForge through 20230101 allows command injection via crafted filenames. (CVE-2024-25081)

Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files. (CVE-2024-25082)


Affected Packages:

fontforge


Issue Correction:
Run dnf update fontforge --releasever 2023.4.20240319 to update your system.

New Packages:
aarch64:
    fontforge-devel-20201107-3.amzn2023.0.3.aarch64
    fontforge-debuginfo-20201107-3.amzn2023.0.3.aarch64
    fontforge-debugsource-20201107-3.amzn2023.0.3.aarch64
    fontforge-20201107-3.amzn2023.0.3.aarch64

noarch:
    fontforge-doc-20201107-3.amzn2023.0.3.noarch

src:
    fontforge-20201107-3.amzn2023.0.3.src

x86_64:
    fontforge-debuginfo-20201107-3.amzn2023.0.3.x86_64
    fontforge-devel-20201107-3.amzn2023.0.3.x86_64
    fontforge-debugsource-20201107-3.amzn2023.0.3.x86_64
    fontforge-20201107-3.amzn2023.0.3.x86_64