PT-2023-9081 · Deepin · Deepin-Reader
Febinrev
·
Publicado
2023-12-22
·
Atualizado
2024-06-15
·
CVE-2023-50254
CVSS v2.0
9.4
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Deepin Linux's default document reader
deepin-reader versions prior to 6.0.7Description
The issue is caused by a design flaw in the
deepin-reader software, leading to remote command execution via crafted docx documents. This is a file overwrite vulnerability, where remote code execution (RCE) can be achieved by overwriting files like .bash rc, .bash login, etc. RCE will be triggered when the user opens the terminal.Recommendations
For versions prior to 6.0.7, update to version 6.0.7, which contains a patch for the issue. As a temporary workaround, consider avoiding the use of
deepin-reader for opening docx documents from untrusted sources until the issue is resolved. Restrict access to sensitive files and directories to minimize the risk of exploitation.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Deepin-Reader