Font security 'still a Helvetica of a problem' says Australian graphics outfit Canva

日本 ニュース ニュース

Font security 'still a Helvetica of a problem' says Australian graphics outfit Canva
日本 最新ニュース,日本 見出し
  • 📰 TheRegister
  • ⏱ Reading Time:
  • 12 sec. here
  • 2 min. at publisher
  • 📊 Quality Score:
  • News: 8%
  • Publisher: 61%

Who knew that unzipping a font archive could unleash a malicious file

The researchers were able to construct a simple proof of concept in the form of a shell execution that allowed FontForge to open files to which it shouldn't have access – which is bad.

"The filename comes from the ArchiveParseTOC function, which means we can create an archive containing a malicious filename, bypassing traditional filename sanitization techniques, and triggering our exploit."

このニュースをすぐに読めるように要約しました。ニュースに興味がある場合は、ここで全文を読むことができます。 続きを読む:

TheRegister /  🏆 67. in UK

日本 最新ニュース, 日本 見出し



Render Time: 2025-04-22 08:03:55