Amazon Linux 2023 Security Advisory: ALAS2023-2024-565
Advisory Released Date: 2024-03-21
Advisory Updated Date: 2024-03-21
Severity:
Medium
Issue Overview:
Splinefont in FontForge through 20230101 allows command injection via crafted filenames. (CVE-2024-25081)
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files. (CVE-2024-25082)
Affected Packages:
fontforge
Issue Correction:
Run dnf update fontforge --releasever 2023.4.20240319 to update your system.
New Packages:
aarch64:
fontforge-devel-20201107-3.amzn2023.0.3.aarch64
fontforge-debuginfo-20201107-3.amzn2023.0.3.aarch64
fontforge-debugsource-20201107-3.amzn2023.0.3.aarch64
fontforge-20201107-3.amzn2023.0.3.aarch64
noarch:
fontforge-doc-20201107-3.amzn2023.0.3.noarch
src:
fontforge-20201107-3.amzn2023.0.3.src
x86_64:
fontforge-debuginfo-20201107-3.amzn2023.0.3.x86_64
fontforge-devel-20201107-3.amzn2023.0.3.x86_64
fontforge-debugsource-20201107-3.amzn2023.0.3.x86_64
fontforge-20201107-3.amzn2023.0.3.x86_64