• 公告ID (KylinSec-SA-2024-1591)

摘要:

fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker to resolve arbitrary entities when a candidate font (OT-SVG fonts), which contains a SVG table, is parsed. This allows attackers to include arbitrary files from the filesystem fontTools is running on or make web requests from the host system. This vulnerability has been patched in version 4.43.0.

安全等级: Low

公告ID: KylinSec-SA-2024-1591

发布日期: 2024年5月27日

关联CVE: CVE-2023-45139  

  • 详细介绍

1. 漏洞描述

   

fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker to resolve arbitrary entities when a candidate font (OT-SVG fonts), which contains a SVG table, is parsed. This allows attackers to include arbitrary files from the filesystem fontTools is running on or make web requests from the host system. This vulnerability has been patched in version 4.43.0.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2023-45139 KY3.4-4A google-noto-emoji-fonts Unaffected
CVE-2023-45139 KY3.4-5 google-noto-emoji-fonts Unaffected
CVE-2023-45139 KY3.5.1 google-noto-emoji-fonts Unaffected
CVE-2023-45139 KY3.5.2 google-noto-emoji-fonts Unaffected
CVE-2023-45139 V6 google-noto-emoji-fonts Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2024-1590 下一篇:KylinSec-SA-2024-1592