Font security 'still a Helvetica of a problem' says Australian graphics outfit Canva
ID: 0e1c388c-c349-55ff-a3d3-3227e4614791
STIX ID: report--0e1c388c-c349-55ff-a3d3-3227e4614791
Feed Name: The Register (Security)
Canva researchers identified three font-related vulnerabilities—CVE-2023-45139 (high severity) affecting FontTools and CVE-2024-25081 / CVE-2024-25082 (lower severity) tied to filename and archive parsing—that can expose sensitive files or lead to command injection in font tools such as FontForge and ImageMagick; PoCs demonstrate exploitation vectors via SVG/XML subsetting and malicious archive TOC/filenames, and Canva recommends treating fonts as untrusted input and increasing research into font security.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
