lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by a --proxy-pac-file argument, because the GNU Guile code uses the system Scheme procedure instead of the system* Scheme procedure. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-17523.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade lilypond | Jul 30, 2024 | May 11, 2018 |
| Suse | — | Upgrade lilypond-doc-deUpgrade lilypond-debuginfoUpgrade lilypond-doc-esUpgrade lilypond-doc-huUpgrade lilypond-century-schoolbook-l-fontsUpgrade lilypond-docUpgrade lilypond-doc-nlUpgrade lilypondUpgrade lilypond-doc-zhUpgrade lilypond-debugsourceUpgrade lilypond-doc-jaUpgrade lilypond-doc-itUpgrade lilypond-doc-csUpgrade lilypond-fonts-commonUpgrade lilypond-doc-frUpgrade lilypond-emmentaler-fonts | May 22, 2018 | May 11, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | May 11, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub