UbuntuUpdates.org

Package "python3-fonttools"

Name: python3-fonttools

Description:

Converts OpenType and TrueType fonts to and from XML (Python 3 Library)

Latest version: 4.55.3-2ubuntu0.25.04.1
Release: plucky (25.04)
Level: security
Repository: universe
Head package: fonttools
Homepage: https://github.com/fonttools/fonttools

Links


Download "python3-fonttools"


Other versions of "python3-fonttools" in Plucky

Repository Area Version
base universe 4.55.3-2build1
updates universe 4.55.3-2ubuntu0.25.04.1

Changelog

Version: 4.55.3-2ubuntu0.25.04.1 2025-12-09 21:54:11 UTC

  fonttools (4.55.3-2ubuntu0.25.04.1) plucky-security; urgency=medium

   * SECURITY UPDATE: Arbitrary File Write and XML injection
     in fontTools.varLib
    - debian/patches/CVE-2025-66034.patch: varLib: only use
      the basename(vf.filename).
    - CVE-2025-66034

 -- Nick Galanis <email address hidden> Tue, 09 Dec 2025 12:30:26 +0000

CVE-2025-66034 fontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttools varLib (or python3 -m fontT



About   -   Send Feedback to @ubuntu_updates