XML External Entity injection in fontTools - CVE-2023-45139
Published: February 7, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied XML input when parsing SVG table. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.
Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.
Affected software
openEuler
Ubuntu
Anolis OS
Fedora
fonttools (Ubuntu package)
fonttools
fonttools-help
python3-fonttools
python3-fonttools+ufo
fonttools-doc
python3-fonttools+woff
python3-fonttools+unicode
python3-fonttools+type1
python3-fonttools+symfont
python3-fonttools+plot
python3-fonttools+lxml
python3-fonttools+interpolatable
python3-fonttools+graphite
How to mitigate CVE-2023-45139
fonttools (Ubuntu package) - addressed in versions 4.29.1-2ubuntu0.1~esm1, 4.46.0-1ubuntu0.1~esm1, 4.55.3-2ubuntu0.25.04.1, 4.55.3-2ubuntu0.25.10.1
fonttools - update to 4.39.4-2
fonttools-help - update to 4.39.4-2
python3-fonttools - update to 4.39.4-2
fonttools - update to 4.43.1-1.fc39
python3-fonttools+ufo - update to 4.47.0-1
fonttools-doc - update to 4.47.0-1
python3-fonttools - update to 4.47.0-1
python3-fonttools+woff - update to 4.47.0-1
python3-fonttools+unicode - update to 4.47.0-1
python3-fonttools+type1 - update to 4.47.0-1
python3-fonttools+symfont - update to 4.47.0-1
python3-fonttools+plot - update to 4.47.0-1
python3-fonttools+lxml - update to 4.47.0-1
python3-fonttools+interpolatable - update to 4.47.0-1
python3-fonttools+graphite - update to 4.47.0-1
fonttools - update to 4.47.0-1
External References
- https://github.com/fonttools/fonttools/security/advisories/GHSA-6673-4983-2vx5
- https://github.com/fonttools/fonttools/commit/9f61271dc1ca82ed91f529b130fe5dc5c9bf1f4c
- https://github.com/fonttools/fonttools/releases/tag/4.43.0
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VY63B4SGY4QOQGUXMECRGD6K3YT3GJ75/