PT-2018-1095 · Leptonica+1 · Leptonica+1

CVE-2018-7440

·

Publicado

2018-02-15

·

Atualizado

2024-12-19

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Leptonica versions through 1.75.3
Description The issue is related to the gplotMakeOutput function in the Leptonica library, which is associated with insufficient input data cleaning. This can allow a remote attacker to execute arbitrary commands using the gplot rootname argument. The problem exists due to an incomplete fix for a previous issue.
Recommendations For versions through 1.75.3, as a temporary workaround, consider restricting the use of the gplotMakeOutput function until a patch is available. Avoid using the gplot rootname argument in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Correção

OS Command Injection

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2021-3559
ALT-PU-2022-1147
ALT-PU-2024-16902
BDU:2018-00492
CVE-2018-7440
DLA-1302-1
MGASA-2018-0279
OPENSUSE-SU-2024:10914-1

Produtos afetados

Alt Linux
Leptonica