yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2024-25082
Component Overview
Vulnerability Overview
Name
CVE-2024-25082
Source
NVD (
link
)
Debian (
link
)
Description
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
CWEs
CWE-77
Published Date
Feb 26, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://www.openwall.com/lists/oss-security/2024/03/08/2
Mailing List
https://fontforge.org/en-US/downloads/
Product
https://github.com/fontforge/fontforge/pull/5367
Patch
https://lists.debian.org/debian-lts-announce/2024/03/msg00007.html
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GCH22HIO2C6M4BZWF5EYIWVFBXL5BQAH/
Issue Tracking
http://www.openwall.com/lists/oss-security/2024/03/08/2
Mailing List
https://fontforge.org/en-US/downloads/
Product
https://github.com/fontforge/fontforge/pull/5367
Patch
https://lists.debian.org/debian-lts-announce/2024/03/msg00007.html
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GCH22HIO2C6M4BZWF5EYIWVFBXL5BQAH/
Issue Tracking
Analysis
#
Affected Component
Analysis
fontforge
Patched
Vulnerability Ratings
#
6.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
fontforge
yocto
master
20251009
Not Affected
fontforge
yocto
scarthgap
20230101
Patched
Resolved with patches
#
fontforge (yocto:kirkstone)
#
Title
Author
Resolve
1
fix splinefont shell command injection
Peter Kydas <pk@canva.com>
CVE-2024-25081
CVE-2024-25082
fontforge (yocto:scarthgap)
#
Title
Author
Resolve
1
fix splinefont shell command injection (#5367)
Peter Kydas <pk@canva.com>
CVE-2024-25081
CVE-2024-25082