﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
19545	Fix CVE-2024-25081 and CVE-2024-25082 in FontForge	Douglas R. Reno	Douglas R. Reno	"Noticed on oss-security:

- CVE-2024-25081 & CVE-2024-25082 in FontForge, fixed in git repo

   FontForge used the system() function to execute commands to unpack fonts
   from archives, and the command line arguments it provides include both the
   name of the archive and the name of a font file specified inside the archive,
   leading to a classic command injection vulnerability if used to unpack a
   specially-named or a specially-crafted archive file.

   A patch to switch from system() to glib's g_spawn_sync() was merged
   upstream on Feb. 6, but there don't seem to be any new releases yet:
   https://github.com/fontforge/fontforge/pull/5367
"	enhancement	closed	elevated	12.2	BOOK	git	medium	fixed		
