An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4. A specially crafted gplot rootname argument can cause a command injection resulting in arbitrary code execution. An attacker can provide a malicious path as input to an application that passes attacker data to this function to trigger this vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade leptonlib | Feb 25, 2019 | Apr 24, 2018 |
| Suse | — | Upgrade leptonica-tools-debuginfoUpgrade liblept4-debuginfo-32bitUpgrade leptonica-develUpgrade liblept4-debuginfoUpgrade liblept4Upgrade leptonica-toolsUpgrade liblept4-32bitUpgrade leptonica-debugsource | Mar 2, 2020 | Feb 12, 2018 |
| Ubuntu | — | Upgrade liblept4 (Ubuntu Pro)Upgrade liblept5 (Ubuntu Pro) | Mar 22, 2023 | Apr 24, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub