PT-2023-9081 · Deepin · Deepin-Reader
Febinrev
·
Published
2023-12-22
·
Updated
2024-06-15
·
CVE-2023-50254
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Deepin Linux's default document reader
deepin-reader versions prior to 6.0.7Description
The issue is caused by a design flaw in the
deepin-reader software, leading to remote command execution via crafted docx documents. This is a file overwrite vulnerability, where remote code execution (RCE) can be achieved by overwriting files like .bash rc, .bash login, etc. RCE will be triggered when the user opens the terminal.Recommendations
For versions prior to 6.0.7, update to version 6.0.7, which contains a patch for the issue. As a temporary workaround, consider avoiding the use of
deepin-reader for opening docx documents from untrusted sources until the issue is resolved. Restrict access to sensitive files and directories to minimize the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Deepin-Reader