Changeset 044207b


Ignore:
Timestamp:
04/15/2024 07:45:04 PM (4 weeks ago)
Author:
Douglas R. Reno <renodr@…>
Branches:
lazarus, trunk
Children:
10f894a9
Parents:
2a7351fd
Message:

FontForge: Fix CVE-2024-25081 and CVE-2024-25082.

Files:
2 edited

Legend:

Unmodified
Added
Removed
  • introduction/welcome/changelog.xml

    r2a7351fd r044207b  
    4242      <para>April 15th, 2024</para>
    4343      <itemizedlist>
     44        <listitem>
     45          <para>[renodr] - Fix CVE-2024-25081 and CVE-2024-25082 in FontForge.
     46          Fixes <ulink url="&blfs-ticket-root;19545">#19545</ulink>.</para>
     47        </listitem>
    4448        <listitem>
    4549          <para>[renodr] - Update to libxcb-1.17.0. Fixes
  • xsoft/other/fontforge.xml

    r2a7351fd r044207b  
    7373      </listitem>
    7474    </itemizedlist>
     75
     76    <bridgehead renderas="sect3">Additional Downloads</bridgehead>
     77    <itemizedlist spacing="compact">
     78      <listitem>
     79        <para>
     80          Required patch:
     81          <ulink url="&patch-root;/fontforge-&fontforge-version;-security_fixes-1.patch"/>
     82        </para>
     83      </listitem>
     84    </bridgehead>
    7585
    7686    <bridgehead renderas="sect3">FontForge Dependencies</bridgehead>
     
    112122      <xref linkend="libjpeg"/>,
    113123      <xref linkend="libtiff"/>,
    114       <xref linkend="sphinx"/> (to build html documentation),
    115       <xref linkend="woff2"/>, and
     124      <xref linkend="sphinx"/> (to build html documentation), and
     125      <xref linkend="woff2"/>
    116126    </para>
    117127
     
    122132
    123133    <para>
    124       First fix a problem with old translations exposed by gettext-0.22:
     134      First, fix two security vulnerabilities in the Splinefont functionality:
     135    </para>
     136
     137<screen><userinput remap="pre">patch -Np1 -i ../fontforge-&fontforge-version;-security_fixes-1.patch</userinput></screen>
     138
     139    <para>
     140      Next, fix a problem with old translations exposed by gettext-0.22:
    125141    </para>
    126142
Note: See TracChangeset for help on using the changeset viewer.