Splinefont in FontForge through 20230101 allows command injection via crafted filenames.
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Link | Tags |
---|---|
https://fontforge.org/en-US/downloads/ | product |
https://github.com/fontforge/fontforge/pull/5367 | patch |
https://lists.debian.org/debian-lts-announce/2024/03/msg00007.html | third party advisory mailing list |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GCH22HIO2C6M4BZWF5EYIWVFBXL5BQAH/ | vendor advisory mailing list issue tracking |
http://www.openwall.com/lists/oss-security/2024/03/08/2 | third party advisory mailing list |