{"id":"CVE-2024-25082","details":"Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.","modified":"2026-08-12T03:51:30.346655877Z","published":"2024-02-26T00:00:00Z","related":["ALSA-2024:4267","ALSA-2024:9439","CGA-59v9-qwpv-rvhg","SUSE-SU-2024:0863-1","SUSE-SU-2024:0864-1"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/25xxx/CVE-2024-25082.json"},"references":[{"type":"WEB","url":"https://fontforge.org/en-US/downloads/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCH22HIO2C6M4BZWF5EYIWVFBXL5BQAH/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/25xxx/CVE-2024-25082.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GCH22HIO2C6M4BZWF5EYIWVFBXL5BQAH/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-25082"},{"type":"FIX","url":"https://github.com/fontforge/fontforge/pull/5367"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2024/03/08/2"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2024/03/msg00007.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/fontforge/fontforge","events":[{"introduced":"0"},{"fixed":"a1dad3e81da03d5d5f3c4c1c1b9b5ca5ebcfcecf"}],"database_specific":{"cpe":"cpe:2.3:a:fontforge:fontforge:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"20230101"},{"last_affected":"20230101"}],"source":["DESCRIPTION","CPE_RANGE"]}}],"versions":["20220308","20201107","20200314","20190801","20190413","20190317","20170731","20170730","20161012","20161005","20161004","20161001","20160930","20150330","20160404","20160403","20150824","20150612","20150430","20150228","v2.1.0","20141230","20141126","20141014","20141013","2.0.20140101","v20120731-b","v20110222"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-25082.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}