Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:4267 - Security Advisory
Issued:
2024-07-02
Updated:
2024-07-02

RHSA-2024:4267 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: fontforge security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for fontforge is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

FontForge is a font editor for outline and bitmap fonts. It supports a range of font formats, including PostScript (ASCII and binary Type 1, some Type 3 and Type 0), TrueType, OpenType (Type2) and CID-keyed fonts.

Security Fix(es):

  • fontforge: command injection via crafted filenames (CVE-2024-25081)
  • fontforge: command injection via crafted archives or compressed files (CVE-2024-25082)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat CodeReady Linux Builder for x86_64 8 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 8 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 8 s390x

Fixes

  • BZ - 2266180 - CVE-2024-25082 fontforge: command injection via crafted archives or compressed files
  • BZ - 2266181 - CVE-2024-25081 fontforge: command injection via crafted filenames

CVEs

  • CVE-2024-25081
  • CVE-2024-25082

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat CodeReady Linux Builder for x86_64 8

SRPM
fontforge-20200314-6.el8_10.src.rpm SHA-256: 5b7d432c8e59c0bc431c4f98b6224949daa163d64c53b94d466b4c8ff2e6ba45
x86_64
fontforge-20200314-6.el8_10.i686.rpm SHA-256: a1b0a14c00b23e43a10c82f11df24f1e374f5b18a601cd8bfc067e6edde2394f
fontforge-20200314-6.el8_10.x86_64.rpm SHA-256: a27ca470d8193fd6a3a7e2c72a8077e216aba4fb8753ab4afd34ea283faf0e84
fontforge-debuginfo-20200314-6.el8_10.i686.rpm SHA-256: 9d07023ee540a5da9495d197bff5b6d8b8706a3e4ca7ac5b1cd8627b9baea134
fontforge-debuginfo-20200314-6.el8_10.x86_64.rpm SHA-256: 32c973923498d20d5a685f7ddb6f37d9434c9cde93cfb7aa5ef12a36ef916c84
fontforge-debugsource-20200314-6.el8_10.i686.rpm SHA-256: 700aa15e5ffea6cad01619f9c189cdb6b468a1e342f0a96d8e4e7de3a0af3b82
fontforge-debugsource-20200314-6.el8_10.x86_64.rpm SHA-256: 9c4e7fef29fa396a77d5ed2a92e84ea67bae86a4742ae7030d04b0e822fea438

Red Hat CodeReady Linux Builder for Power, little endian 8

SRPM
fontforge-20200314-6.el8_10.src.rpm SHA-256: 5b7d432c8e59c0bc431c4f98b6224949daa163d64c53b94d466b4c8ff2e6ba45
ppc64le
fontforge-20200314-6.el8_10.ppc64le.rpm SHA-256: c5e57112ffb7261c5407fd6fa221be9c4397dd81f18af1039b23cc2133bfb858
fontforge-debuginfo-20200314-6.el8_10.ppc64le.rpm SHA-256: 921cc6a32119709d807791e2e32402515985cba79071e748f6235b84e720e2fb
fontforge-debugsource-20200314-6.el8_10.ppc64le.rpm SHA-256: ed8f8b6ef72ffc1dfe93a837b7d2146556ad66a7b591f9cacc488e22474ffc3c

Red Hat CodeReady Linux Builder for ARM 64 8

SRPM
fontforge-20200314-6.el8_10.src.rpm SHA-256: 5b7d432c8e59c0bc431c4f98b6224949daa163d64c53b94d466b4c8ff2e6ba45
aarch64
fontforge-20200314-6.el8_10.aarch64.rpm SHA-256: 780d3391e37710166d94f532ed585c747e721f1f1563bf59bbe07cf265c04453
fontforge-debuginfo-20200314-6.el8_10.aarch64.rpm SHA-256: 0423172aae18f42f7d67ced0389c7ce2aa3535f38575b373d9bfa28d65921fcd
fontforge-debugsource-20200314-6.el8_10.aarch64.rpm SHA-256: 6dc66b99f2496f75b4e3b1adb05c3aaf29d4de0ecd2924c07cddccb916da00b8

Red Hat CodeReady Linux Builder for IBM z Systems 8

SRPM
fontforge-20200314-6.el8_10.src.rpm SHA-256: 5b7d432c8e59c0bc431c4f98b6224949daa163d64c53b94d466b4c8ff2e6ba45
s390x
fontforge-20200314-6.el8_10.s390x.rpm SHA-256: 54eb437d11e2a87161dbe50c0e1902d18da2f1b5a2ac39f8c185c5297845e44d
fontforge-debuginfo-20200314-6.el8_10.s390x.rpm SHA-256: 05fac7f1fec431cbcc40b1aba2c6e3711d76cabb95f3fb19cccb091f07e59670
fontforge-debugsource-20200314-6.el8_10.s390x.rpm SHA-256: 1feeb0a2f1f5cbaaf98994fe606f1f2cc96102332366dbaf2f2c32b1c2a5199a

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility