UbuntuUpdates.org

Package "fonttools"

Name: fonttools

Description:

Converts OpenType and TrueType fonts to and from XML (Executables)

Latest version: 4.55.3-2ubuntu0.25.04.1
Release: plucky (25.04)
Level: updates
Repository: universe
Homepage: https://github.com/fonttools/fonttools

Links


Download "fonttools"


Other versions of "fonttools" in Plucky

Repository Area Version
base universe 4.55.3-2build1
security universe 4.55.3-2ubuntu0.25.04.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 4.55.3-2ubuntu0.25.04.1 2025-12-10 01:22:11 UTC

  fonttools (4.55.3-2ubuntu0.25.04.1) plucky-security; urgency=medium

   * SECURITY UPDATE: Arbitrary File Write and XML injection
     in fontTools.varLib
    - debian/patches/CVE-2025-66034.patch: varLib: only use
      the basename(vf.filename).
    - CVE-2025-66034

 -- Nick Galanis <email address hidden> Tue, 09 Dec 2025 12:30:26 +0000

CVE-2025-66034 fontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttools varLib (or python3 -m fontT



About   -   Send Feedback to @ubuntu_updates