File _patchinfo of Package patchinfo.32866
<patchinfo incident="32866"> <issue tracker="cve" id="2024-25081"/> <issue tracker="cve" id="2024-25082"/> <issue tracker="bnc" id="1220404">VUL-0: CVE-2024-25081: fontforge: command injection via crafted filenames</issue> <issue tracker="bnc" id="1220405">VUL-0: CVE-2024-25082: fontforge: command injection via crafted archives or compressed files</issue> <packager>qzhao</packager> <rating>important</rating> <category>security</category> <summary>Security update for fontforge</summary> <description>This update for fontforge fixes the following issues: - CVE-2024-25081: Fixed command injection via crafted filenames (bsc#1220404). - CVE-2024-25082: Fixed command injection via crafted archives or compressed files (bsc#1220405). </description> </patchinfo>