Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-15276

Опубликовано: 31 дек. 2025
Источник: redhat
CVSS3: 7.8

Описание

FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SFD files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28198.

A flaw was found in FontForge. A remote attacker could exploit this vulnerability by enticing a user to open a specially crafted SFD file. This issue arises from improper validation of user-supplied data during SFD file parsing, leading to deserialization of untrusted data. Successful exploitation could result in arbitrary code execution in the context of the current process.

Отчет

This vulnerability is rated Important for Red Hat products as it allows for arbitrary code execution in FontForge. Exploitation requires user interaction, where a target must open a specially crafted SFD file. FontForge is shipped in Red Hat Enterprise Linux 6, 7, 8, 9, 10, Fedora, and Red Hat In-Vehicle OS.

Меры по смягчению последствий

To mitigate this issue, users should avoid opening SFD files from untrusted sources. If FontForge is not essential for system operation, consider removing the fontforge package to eliminate the attack vector. This action may impact functionality dependent on FontForge.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10fontforgeAffected
Red Hat Enterprise Linux 6fontforgeOut of support scope
Red Hat Enterprise Linux 7fontforgeAffected
Red Hat Enterprise Linux 8fontforgeAffected
Red Hat Enterprise Linux 9fontforgeAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2426424fontforge: FontForge: Remote Code Execution via SFD File Parsing Deserialization of Untrusted Data

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
8 месяцев назад

FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SFD files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28198.

CVSS3: 7.8
nvd
8 месяцев назад

FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SFD files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28198.

CVSS3: 7.8
debian
8 месяцев назад

FontForge SFD File Parsing Deserialization of Untrusted Data Remote Co ...

CVSS3: 7.8
github
8 месяцев назад

FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SFD files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28198.

7.8 High

CVSS3

Уязвимость CVE-2025-15276