Splinefont in FontForge through 20230101 allows command injection via crafted filenames. https://github.com/fontforge/fontforge/pull/5367
Created fontforge tracking bugs for this issue: Affects: fedora-all [bug 2266182]
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:4267 https://access.redhat.com/errata/RHSA-2024:4267
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:9439 https://access.redhat.com/errata/RHSA-2024:9439