PT-2018-1095 · Leptonica+1 · Leptonica+1

Published

2018-02-15

·

Updated

2024-12-19

·

CVE-2018-7440

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Leptonica versions through 1.75.3
Description The issue is related to the gplotMakeOutput function in the Leptonica library, which is associated with insufficient input data cleaning. This can allow a remote attacker to execute arbitrary commands using the gplot rootname argument. The problem exists due to an incomplete fix for a previous issue.
Recommendations For versions through 1.75.3, as a temporary workaround, consider restricting the use of the gplotMakeOutput function until a patch is available. Avoid using the gplot rootname argument in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3559
ALT-PU-2022-1147
ALT-PU-2024-16902
BDU:2018-00492
CVE-2018-7440
DLA-1302-1
MGASA-2018-0279
OPENSUSE-SU-2024:10914-1

Affected Products

Alt Linux
Leptonica