Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0267 | fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker to resolve arbitrary entities when a candidate font (OT-SVG fonts), which contains a SVG table, is parsed. This allows attackers to include arbitrary files from the filesystem fontTools is running on or make web requests from the host system. This vulnerability has been patched in version 4.43.0. |
Github GHSA |
GHSA-6673-4983-2vx5 | fonttools XML External Entity Injection (XXE) Vulnerability |
Ubuntu USN |
USN-7917-1 | fontTools vulnerabilities |
Tue, 03 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-03T14:27:45.728Z
Reserved: 2023-10-04T16:02:46.329Z
Link: CVE-2023-45139
Updated: 2024-08-02T20:14:19.258Z
Status : Modified
Published: 2024-01-10T16:15:46.767
Modified: 2024-11-21T08:26:25.513
Link: CVE-2023-45139
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN