PT-2017-14833 · Lilypond · Lilypond

Gabriel Corona

·

Publicado

2017-12-11

·

Atualizado

2018-10-26

·

CVE-2017-17523

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LilyPond versions prior to 2.19.80
Description The issue concerns the failure to validate strings before launching a program specified by the BROWSER environment variable. This allows remote attackers to conduct argument-injection attacks via a crafted URL, such as using the --proxy-pac-file argument.
Recommendations For versions prior to 2.19.80, update to version 2.19.80 or later to resolve the issue. As a temporary workaround, consider restricting the use of the BROWSER environment variable to minimize the risk of exploitation.

Correção

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-17523
MGASA-2018-0412

Produtos afetados

Lilypond