Amazon Linux 2023 Security Advisory: ALAS-2024-565
Advisory Release Date: 2024-03-13 20:41 Pacific
Advisory Updated Date: 2024-03-21 14:00 Pacific
Splinefont in FontForge through 20230101 allows command injection via crafted filenames. (CVE-2024-25081)
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files. (CVE-2024-25082)
Affected Packages:
fontforge
Issue Correction:
Run dnf update fontforge --releasever 2023.4.20240319 to update your system.
aarch64:
fontforge-devel-20201107-3.amzn2023.0.3.aarch64
fontforge-debuginfo-20201107-3.amzn2023.0.3.aarch64
fontforge-debugsource-20201107-3.amzn2023.0.3.aarch64
fontforge-20201107-3.amzn2023.0.3.aarch64
noarch:
fontforge-doc-20201107-3.amzn2023.0.3.noarch
src:
fontforge-20201107-3.amzn2023.0.3.src
x86_64:
fontforge-debuginfo-20201107-3.amzn2023.0.3.x86_64
fontforge-devel-20201107-3.amzn2023.0.3.x86_64
fontforge-debugsource-20201107-3.amzn2023.0.3.x86_64
fontforge-20201107-3.amzn2023.0.3.x86_64