PT-2023-9081 · Deepin · Deepin-Reader

Febinrev

·

Published

2023-12-22

·

Updated

2024-06-15

·

CVE-2023-50254

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions Deepin Linux's default document reader deepin-reader versions prior to 6.0.7
Description The issue is caused by a design flaw in the deepin-reader software, leading to remote command execution via crafted docx documents. This is a file overwrite vulnerability, where remote code execution (RCE) can be achieved by overwriting files like .bash rc, .bash login, etc. RCE will be triggered when the user opens the terminal.
Recommendations For versions prior to 6.0.7, update to version 6.0.7, which contains a patch for the issue. As a temporary workaround, consider avoiding the use of deepin-reader for opening docx documents from untrusted sources until the issue is resolved. Restrict access to sensitive files and directories to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03480
CVE-2023-50254
GHSA-Q9JR-726G-9495
OPENSUSE-SU-2024:13536-1

Affected Products

Deepin-Reader