Description
uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a different vulnerability than CVE-2017-17534.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 12 | | =1:20230101~dfsg-1 || =1:20230101~dfsg-1.1 || =1:20230101~dfsg-1.1~deb12u1 || =1:20230101~dfsg-2 || =1:20230101~dfsg-3 || =1:20230101~dfsg-4 || =1:20230101~dfsg-5 || =1:20230101~dfsg-6 || =1:20230101~dfsg-7 || =1:20230101~dfsg-8 |
 debian 13 | | =1:20230101~dfsg-4 || =1:20230101~dfsg-5 || =1:20230101~dfsg-6 || =1:20230101~dfsg-7 || =1:20230101~dfsg-8 |
 debian 11 | | =1:20201107~dfsg-4 || =1:20201107~dfsg-4+deb11u1 || =1:20220308~dfsg-1 || =1:20230101~dfsg-1 || =1:20230101~dfsg-1.1 || =1:20230101~dfsg-1.1~deb12u1 || =1:20230101~dfsg-2 || =1:20230101~dfsg-3 || =1:20230101~dfsg-4 || =1:20230101~dfsg-5 || =1:20230101~dfsg-6 || =1:20230101~dfsg-7 || =1:20230101~dfsg-8 |
 debian 14 | | =1:20230101~dfsg-4 || =1:20230101~dfsg-5 || =1:20230101~dfsg-6 || =1:20230101~dfsg-7 || =1:20230101~dfsg-8 |
 rpm rhel6 | | - |
 rpm rhel8 | | - |
 rpm rhel7 | | - |