An issue was discovered in pixHtmlViewer in prog/htmlviewer.c in Leptonica before 1.75.3. Unsanitized input (rootname) can overflow a buffer, leading potentially to arbitrary code execution or possibly unspecified other impact.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade leptonlib | Jul 30, 2024 | Feb 19, 2018 |
| Gentoo Linux | — | Upgrade media-libs/leptonica. | Dec 19, 2023 | Feb 19, 2018 |
| Suse | — | Upgrade liblept4-debuginfo-32bitUpgrade leptonica-develUpgrade liblept4-debuginfoUpgrade leptonica-tools-debuginfoUpgrade liblept4Upgrade liblept4-32bitUpgrade leptonica-toolsUpgrade leptonica-debugsource | Mar 10, 2018 | Feb 19, 2018 |
| Ubuntu | — | Upgrade leptonica-progs (Ubuntu Pro)Upgrade liblept5 (Ubuntu Pro) | Mar 22, 2023 | Feb 19, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub