File _patchinfo of Package patchinfo.32866
<patchinfo incident="32866">
<issue tracker="cve" id="2024-25081"/>
<issue tracker="cve" id="2024-25082"/>
<issue tracker="bnc" id="1220404">VUL-0: CVE-2024-25081: fontforge: command injection via crafted filenames</issue>
<issue tracker="bnc" id="1220405">VUL-0: CVE-2024-25082: fontforge: command injection via crafted archives or compressed files</issue>
<packager>qzhao</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for fontforge</summary>
<description>This update for fontforge fixes the following issues:
- CVE-2024-25081: Fixed command injection via crafted filenames (bsc#1220404).
- CVE-2024-25082: Fixed command injection via crafted archives or compressed files (bsc#1220405).
</description>
</patchinfo>