https://bugzilla.redhat.com/show_bug.cgi?id=2421328

            Bug ID: 2421328
           Summary: CVE-2025-66034 fonttools: fontTools: Arbitrary file
                    write leading to remote code execution via malicious
                    .designspace file [epel-9]
           Product: Fedora EPEL
           Version: epel9
            Status: NEW
        Whiteboard: {"flaws": ["d20a521f-05e5-496a-8c46-da4b603e9920"]}
         Component: fonttools
          Keywords: Security, SecurityTracking
          Severity: medium
          Priority: medium
          Assignee: [email protected]
          Reporter: [email protected]
        QA Contact: [email protected]
                CC: [email protected],
                    [email protected], [email protected]
            Blocks: 2417780 (CVE-2025-66034)
  Target Milestone: ---
    Classification: Fedora



Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.

The following link provides references to all essential vulnerability
management information. If something is wrong or missing, please contact a
member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams



Referenced Bugs:

https://bugzilla.redhat.com/show_bug.cgi?id=2417780
[Bug 2417780] CVE-2025-66034 fonttools: fontTools: Arbitrary file write leading
to remote code execution via malicious .designspace file
-- 
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2421328

Report this comment as SPAM: 
https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-spam&short_desc=Report%20of%20Bug%202421328%23c0

-- 
_______________________________________________
fonts-bugs mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to