Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-25082
HistoryFeb 26, 2024 - 12:00 a.m.

CVE-2024-25082

2024-02-2600:00:00
ubuntu.com
ubuntu.com
10
splinefont
command injection
craft archives
fontforge
unix

7.9 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.8%

Splinefont in FontForge through 20230101 allows command injection via
crafted archives or compressed files.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchfontforge< 1:20170731~dfsg-1ubuntu0.1~esm1UNKNOWN
ubuntu20.04noarchfontforge< 1:20190801~dfsg-4ubuntu0.1UNKNOWN
ubuntu22.04noarchfontforge< 1:20201107~dfsg-4+deb11u1build0.22.04.1UNKNOWN
ubuntu23.10noarchfontforge< 1:20230101~dfsg-1ubuntu0.1UNKNOWN
ubuntu16.04noarchfontforge< 20120731.b-7.1ubuntu0.1+esm1UNKNOWN

7.9 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.8%