An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4. A specially crafted gplot rootname argument can cause a command injection resulting in arbitrary code execution. An attacker can provide a malicious path as input to an application that passes attacker data to this function to trigger this vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade leptonlib | Feb 25, 2019 | Apr 24, 2018 |
| Suse | — | Upgrade liblept4-debuginfo-32bitUpgrade leptonica-tools-debuginfoUpgrade leptonica-develUpgrade leptonica-toolsUpgrade leptonica-debugsourceUpgrade liblept4-32bitUpgrade liblept4Upgrade liblept4-debuginfo | Mar 2, 2020 | Feb 12, 2018 |
| Ubuntu | — | Upgrade liblept5 (Ubuntu Pro)Upgrade liblept4 (Ubuntu Pro) | Mar 22, 2023 | Apr 24, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub