PT-2020-6148 · Lilypond+2 · Lilypond+2

Faidon Liambotis

·

Published

2020-08-05

·

Updated

2024-06-15

·

CVE-2020-17353

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LilyPond versions 2.20.0 and earlier LilyPond versions 2.21.x through 2.21.4
Description The issue is related to a lack of restrictions on embedded-ps and embedded-svg when the -dsafe option is used. This can be exploited by including dangerous PostScript code, potentially allowing an attacker to execute arbitrary code.
Recommendations For LilyPond versions 2.20.0 and earlier, consider disabling the use of embedded-ps and embedded-svg until a patch is available. For LilyPond versions 2.21.x through 2.21.4, restrict the use of embedded-ps and embedded-svg to minimize the risk of exploitation. As a temporary workaround, avoid using the -dsafe option with embedded-ps and embedded-svg until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2599
ALT-PU-2020-2877
ALT-PU-2021-1207
BDU:2021-03182
CVE-2020-17353
DSA-4756-1
MGASA-2020-0414
OPENSUSE-SU-2020:1453-1
OPENSUSE-SU-2020:1506-1
OPENSUSE-SU-2020_1453-1
OPENSUSE-SU-2024:11021-1

Affected Products

Alt Linux
Lilypond
Suse