Command Injection Vulnerability in FontForge's Splinefont Component
CVE-2024-25081

4.2MEDIUM

Key Information:

Vendor

FontForge

Status
Vendor
CVE Published:
26 February 2024

What is CVE-2024-25081?

A vulnerability has been identified in the Splinefont component of FontForge that allows command injection through the use of specially crafted filenames. This flaw indicates that malicious actors could potentially execute arbitrary commands on the affected system. It is crucial for users of FontForge to apply the latest security updates and implement necessary measures to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.